In brief

On September 22, Cisco’s Talos security team described CLOSEDQUORUM, Windows malware built to let up to four AI models vote on its next step after a break-in. Talos also released CAIRN, a free tool that looks for AI use in malware. It has found no victims, and the public sample cannot run as shipped.

New to this? Read it in simple words
  • Security researchers at Cisco Talos described a new kind of Windows malware.
  • After it gets onto a computer, it asks four AI models to vote on its next step.
  • The AI can only choose from four ready-made actions. People still build and spread the malware.
  • Talos has found no victims so far. It also released a free tool that looks for AI inside malware.
Words to know
Malware
Harmful software that criminals use to steal data or damage computers.
Open source
Software whose code anyone can read, use and change.

Four AI models vote on the next move

CLOSEDQUORUM is written in the Go programming language. Talos says it aims to steal Windows logins, browser passwords, and crypto wallets, and to send the stolen data to a chat channel on Discord.

After it reaches a computer, the malware asks models from DeepSeek, Alibaba’s Qwen, Mistral, and Google’s Gemini what to do next. The models vote, and the majority wins. DeepSeek breaks a tie.

The choice is narrow. The models can only pick one of four built-in steps: steal data, inject code, stay on the computer, or move to other machines. Talos found no working code for the last step, and answers in the wrong format are thrown away.

People still build the malware, add the keys for the AI services, send it to victims, and collect what it steals. So “no human operator” describes only the choice of step after the break-in.

Sources1456

THREAT CHECK 03
The AI picks the next step, but only from four actions that people built in.

Talos found no confirmed victims. The public sample has fake keys and cannot run as shipped.

No known victims yet

Talos has not confirmed that anyone used CLOSEDQUORUM against a real target. The public version contains fake keys and a dummy address, so it cannot work as shipped.

According to Talos’s research files, six versions were first seen between December 29, 2025, and January 6, 2026. That makes the samples about nine months old.

Talos links the developer to posts about stolen payment cards on criminal forums in 2025. It names no group and no country. We found no statement from the AI companies whose models the malware calls.

Talos says refusals, usage limits, and blocked keys can break the malware. The AI companies could stop it by cancelling the keys it uses.

Sources134

A “first” with a narrow meaning

Some headlines called CLOSEDQUORUM the first malware controlled by AI. Talos’s own claim is narrower: it is the first publicly documented Windows malware of this kind that Talos knows of.

Earlier cases exist. In February, ESET reported PromptSpy, Android malware that asks Gemini which steps to take on the phone’s screen. In July 2025, Ukraine’s cyber agency CERT-UA described LameHug, which used an AI model to turn text descriptions into commands.

Palo Alto Networks’ Unit 42 team reported in August that about 97 percent of the AI-using malware samples it studied exist only in test environments and on VirusTotal, a large malware database.

CAIRN is open source under the MIT licence. It searches VirusTotal for traces of AI use, such as prompts, the addresses of AI services, and the format of their keys. It never runs the malware it finds.

CAIRN tracks ten published families of AI-using malware so far. Its detection rules do not yet include one for CLOSEDQUORUM.

Sources125789

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Primary source · September 22, 2026The Closed Quorum: Inside the first reported autonomous AI C2 implant Cisco Talos
  2. 2
    Primary source · September 22, 2026Introducing CAIRN: Frontier tracking for AI-integrated malware Cisco Talos
  3. 3
    Primary source · September 2026Cognitive-Artifact-Intelligence-Research-Network (CAIRN) Cisco Talos on GitHub
  4. 4
    Research · September 22, 2026New ClosedQuorum Windows malware uses AI for attack decisions BleepingComputer
  5. 5
  6. 6
  7. 7
    Research · February 19, 2026PromptSpy ushers in the era of Android threats using GenAI ESET WeLiveSecurity
  8. 8
  9. 9
How we checked this story

We read both Talos reports and its research files, then compared BleepingComputer, The Hacker News, and The Register. All technical findings come from Talos, and we found no independent analysis of the samples. We checked earlier AI-malware cases with ESET, CERT-UA reporting, and Unit 42.