News Room
16
Share
New 'ClosedQuorum' Malware Uses Autonomous AI Voting to Execute Cyber Attacks
criticalAI Cyber Attacks

New 'ClosedQuorum' Malware Uses Autonomous AI Voting to Execute Cyber Attacks

A novel Windows malware strain, ClosedQuorum, has emerged, utilizing a multi-model AI voting system to autonomously determine post-compromise attack vectors without human intervention.

24 September 2026Last updated 24 September 20264 min readCisco Talos
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
AI Cyber Attacks
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
Confirmed
Source:
Cisco Talos
Read Time:
4 min

Executive Summary

Security researchers at Cisco Talos have identified a sophisticated new strain of Windows malware dubbed 'ClosedQuorum'. Unlike traditional malware that relies on hardcoded scripts or human-operated command-and-control (C2) infrastructure, ClosedQuorum leverages a decentralized ensemble of Large Language Models (LLMs) to make real-time, autonomous decisions during the post-compromise phase of an attack. This development marks a significant shift toward fully agentic, AI-driven cyber operations.

Threat Analysis

ClosedQuorum represents a departure from standard automated threats. Once the malware gains initial access to a host, it initiates a local reconnaissance phase. Instead of following a pre-programmed playbook, the malware queries a suite of integrated AI models—specifically Google Gemini, DeepSeek, Qwen, and Mistral—to analyze the environment and suggest the most effective next steps, such as lateral movement, privilege escalation, or data exfiltration. The malware operates with zero human oversight, effectively functioning as an autonomous offensive agent.

Technical Details

Written in Go, the malware is designed for modularity and resilience. It employs a unique 'voting system' to reach consensus on its tactical decisions. When the malware identifies a potential target or system vulnerability, it prompts each of the four integrated LLMs to propose an action. These proposals are then weighted and compared. In the event of a tie, the DeepSeek model is hardcoded to hold the tie-breaking authority, followed by Qwen, Mistral, and Gemini. This consensus mechanism allows the malware to adapt its behavior dynamically based on the specific security posture of the infected host, making signature-based detection significantly more difficult.

Attribution Assessment

As of September 24, 2026, no specific threat actor group has been definitively linked to the development of ClosedQuorum. However, the sophistication of the integration suggests the work of a highly capable cybercriminal entity or a state-sponsored research unit experimenting with the weaponization of frontier AI models. The use of multiple commercial and open-source models indicates a deliberate effort to avoid reliance on a single API provider.

Implications

The emergence of ClosedQuorum highlights the growing risk of 'agentic' malware. As AI models become more capable of reasoning and executing complex tasks, the barrier to entry for sophisticated cyber attacks is lowered. Organizations must now contend with threats that can 'think' and adapt in real-time, rendering traditional static defense mechanisms increasingly obsolete.

Recommendations

  1. Implement strict egress filtering to prevent malware from communicating with unauthorized AI model APIs.
  2. Deploy behavioral-based endpoint detection and response (EDR) solutions capable of identifying anomalous process chains, even if the individual actions appear legitimate.
  3. Enhance monitoring of API usage patterns within the corporate network to detect unauthorized queries to LLM services.
  4. Adopt a zero-trust architecture to limit the potential impact of autonomous lateral movement.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo