A new wave of autonomous malware has emerged, threatening Windows users with sophisticated attacks that can be executed without human intervention. ClosedQuorum, a Go-based malware, uses artificial intelligence (AI) models to autonomously decide its next course of action during post-compromise stages of an attack. This marks a significant shift in the world of cybersecurity, as AI-powered malware begins to outmaneuver traditional security measures.
ClosedQuorum relies on four distinct AI models – Google Gemini, DeepSeek, Qwen, and Mistral – to make decisions about how to proceed after infecting a host. These models are used in conjunction with reconnaissance information and a voting system to determine the next step. If votes are tied, DeepSeek takes priority in making the final decision, followed by Qwen, Mistral, and Gemini. This AI-powered approach allows ClosedQuorum to adapt quickly to changing circumstances, making it a formidable opponent for security teams.
The malware’s primary goal is to steal sensitive information from infected hosts. To achieve this, ClosedQuorum employs various techniques, including credential dumping, browser credential theft, and cryptocurrency-wallet extraction. The stolen data is then passed on to the operators via a Discord webhook, eliminating the need for human interaction in the attack chain. Cisco Talos researchers have described ClosedQuorum as the first publicly documented Windows implant to delegate tactical command-and-control (C2) decisions to AI models, highlighting its potential for speed and scaling.
One of the most striking aspects of ClosedQuorum is its ability to proceed with an attack at any time, without human intervention. This eliminates the need for attackers to wait for specific commands or schedules, making it easier to launch a successful assault. However, Cisco notes that this approach also poses challenges in certain cases, such as rate limits being hit or commercial APIs becoming unavailable.
It remains unclear whether ClosedQuorum is a testbed or a fully-fledged malware, but its implications are clear: the use of AI in cyber attacks is becoming increasingly prevalent. As researchers warn, ClosedQuorum represents an “architectural shift towards attack-chain automation,” making it essential for security teams to stay ahead of this trend.
For users and organizations, this development serves as a stark reminder that cybersecurity must evolve to keep pace with emerging threats. By staying informed about the latest developments in AI-powered malware, security professionals can better prepare themselves to combat these attacks. As the threat landscape continues to shift, it is essential to prioritize AI-speed defenses and validate, decide, fix, and re-validate at machine speed.
Source: Bleeping Computer — 2026-09-22