ClosedQuorum Malware Uses Gemini, DeepSeek, Qwen, and Mistral to Guide Attacks


DeepSeek, Qwen, and Mistral AI malware
Image credit: DeepSeek, Alibaba, Mistral AI

ClosedQuorum malware uses AI models to make attack decisions autonomously after compromising Windows systems, according to Cisco Talos.

Researchers say the Go-based malware consults Google Gemini, DeepSeek, Qwen, and Mistral models before deciding what action to take next. It can operate without continuous instructions from a human attacker.

Cisco describes ClosedQuorum as the first publicly documented Windows implant that delegates tactical command-and-control decisions to a panel of AI models. Researchers have not confirmed its use in real-world attacks.

Four AI models vote on the next attack step

ClosedQuorum collects reconnaissance data from the compromised PC and sends that information to the four AI models.

Each model selects from a predefined list of actions. The malware then uses their responses to decide what to do next.

Possible actions include stealing credentials and cryptocurrency wallets, injecting code into processes, establishing persistence, and attempting lateral movement across a network.

ClosedQuorum can automate post-compromise attacks

The malware can target LSASS credentials, data stored in Chrome, Edge, and Firefox, and cryptocurrency wallets.

ClosedQuorum can send stolen information to attackers through a Discord webhook. Because AI models select later actions, much of the attack chain can continue without an operator constantly controlling the malware.

However, its dependence on external AI services also creates limitations. API rate limits, malformed model responses, or temporary service outages could interrupt its autonomous operation.

Cisco also found placeholder API credentials and a dummy Discord webhook in the analyzed sample, suggesting ClosedQuorum may still be experimental.

Talos discovered the malware through CAIRN, its open-source toolkit for identifying and analyzing malware that integrates AI models.

In other security news, a BigDiskBuster zero-day can block Microsoft Defender updates, while researchers also found OpenAI Codex sandbox escapes.

Researchers have also detailed the BragJack attack, which can hijack AI assistants in Chrome, Edge, and other browsers.

Via BleepingComputer

More about the topics: AI, deepseek, Gemini, malware, Mistral AI

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages