
New 'ClosedQuorum' Malware Uses Four-LLM Hive Mind for Autonomous Cyber Attacks
Cisco Talos has identified 'ClosedQuorum,' a novel Windows malware that utilizes a voting system between four different LLMs to autonomously execute post-compromise attack stages without human intervention.
Executive Takeaway — TL;DR
- Category:
- AI Cyber Attacks
- Severity:
- Critical
- Actor Type:
- Unknown
- Geography:
- Global
- Confidence:
- Confirmed
- Source:
- Cisco Talos
- Read Time:
- 4 min
Executive Summary
On September 22, 2026, security researchers at Cisco Talos unveiled a groundbreaking discovery: a new strain of Windows-based malware dubbed 'ClosedQuorum.' This malware represents a significant shift in the threat landscape, as it operates entirely autonomously by leveraging a 'hive mind' of four distinct Large Language Models (LLMs) to make tactical decisions during the post-compromise phase of an attack. The discovery was made possible by the release of CAIRN, a new open-source framework designed by Talos to classify and analyze AI-integrated malicious software.
Threat Analysis
ClosedQuorum is a Go-based implant that eliminates the need for a traditional Command and Control (C2) human operator. Instead of receiving manual instructions, the malware performs local reconnaissance and then queries multiple AI models to determine the most effective next step. This autonomous decision-making capability allows the malware to adapt its behavior in real-time based on the specific environment it has infected, significantly increasing the difficulty for traditional signature-based detection systems to track its progression.
Technical Details
The malware utilizes a sophisticated voting mechanism to reach consensus on its actions. It polls four specific models: Google Gemini, DeepSeek, Qwen, and Mistral. Once the reconnaissance data is processed, each model provides a suggested course of action. The malware then tallies these suggestions. In the event of a tie, the system is hardcoded to prioritize the output of the DeepSeek model, followed by Qwen, Mistral, and Gemini. This multi-model approach ensures that the malware can bypass simple heuristic filters that might be trained to detect the patterns of a single specific LLM.
Attribution Assessment
As of September 24, 2026, Cisco Talos has not attributed ClosedQuorum to a specific nation-state or known cybercriminal group. The use of diverse, publicly available LLM APIs suggests that the developers are focused on creating a highly resilient, modular attack framework rather than relying on proprietary, custom-trained models. The sophistication of the Go-based implementation indicates a high level of technical proficiency among the developers.
Implications
The emergence of ClosedQuorum confirms the warnings issued by the Five Eyes intelligence alliance in June 2026 regarding the rapid acceleration of AI-powered cyber threats. By removing the human-in-the-loop, attackers can scale operations at a speed previously impossible, as the malware can react to defensive measures faster than a human analyst can respond. This development marks a transition from 'AI-assisted' attacks to 'AI-autonomous' operations.
Recommendations
Organizations are advised to implement behavioral-based endpoint detection and response (EDR) solutions that monitor for anomalous process execution patterns rather than relying solely on file hashes. Security teams should also monitor for unusual API traffic patterns originating from internal hosts, as the malware must communicate with external LLM providers to function. Furthermore, adopting the CAIRN framework for internal threat hunting is recommended to better identify AI-integrated malicious activity within enterprise networks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



