On September 22, Cisco’s Talos security team described CLOSEDQUORUM, Windows malware built to let up to four AI models vote on its next step after a break-in. Talos also released CAIRN, a free tool that looks for AI use in malware. It has found no victims, and the public sample cannot run as shipped.
New to this? Read it in simple words
- Security researchers at Cisco Talos described a new kind of Windows malware.
- After it gets onto a computer, it asks four AI models to vote on its next step.
- The AI can only choose from four ready-made actions. People still build and spread the malware.
- Talos has found no victims so far. It also released a free tool that looks for AI inside malware.
- Malware
- Harmful software that criminals use to steal data or damage computers.
- Open source
- Software whose code anyone can read, use and change.
Four AI models vote on the next move
CLOSEDQUORUM is written in the Go programming language. Talos says it aims to steal Windows logins, browser passwords, and crypto wallets, and to send the stolen data to a chat channel on Discord.
After it reaches a computer, the malware asks models from DeepSeek, Alibaba’s Qwen, Mistral, and Google’s Gemini what to do next. The models vote, and the majority wins. DeepSeek breaks a tie.
The choice is narrow. The models can only pick one of four built-in steps: steal data, inject code, stay on the computer, or move to other machines. Talos found no working code for the last step, and answers in the wrong format are thrown away.
People still build the malware, add the keys for the AI services, send it to victims, and collect what it steals. So “no human operator” describes only the choice of step after the break-in.
Talos found no confirmed victims. The public sample has fake keys and cannot run as shipped.
No known victims yet
Talos has not confirmed that anyone used CLOSEDQUORUM against a real target. The public version contains fake keys and a dummy address, so it cannot work as shipped.
According to Talos’s research files, six versions were first seen between December 29, 2025, and January 6, 2026. That makes the samples about nine months old.
Talos links the developer to posts about stolen payment cards on criminal forums in 2025. It names no group and no country. We found no statement from the AI companies whose models the malware calls.
Talos says refusals, usage limits, and blocked keys can break the malware. The AI companies could stop it by cancelling the keys it uses.
A “first” with a narrow meaning
Some headlines called CLOSEDQUORUM the first malware controlled by AI. Talos’s own claim is narrower: it is the first publicly documented Windows malware of this kind that Talos knows of.
Earlier cases exist. In February, ESET reported PromptSpy, Android malware that asks Gemini which steps to take on the phone’s screen. In July 2025, Ukraine’s cyber agency CERT-UA described LameHug, which used an AI model to turn text descriptions into commands.
Palo Alto Networks’ Unit 42 team reported in August that about 97 percent of the AI-using malware samples it studied exist only in test environments and on VirusTotal, a large malware database.
CAIRN is open source under the MIT licence. It searches VirusTotal for traces of AI use, such as prompts, the addresses of AI services, and the format of their keys. It never runs the malware it finds.
CAIRN tracks ten published families of AI-using malware so far. Its detection rules do not yet include one for CLOSEDQUORUM.
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1Primary source · September 22, 2026The Closed Quorum: Inside the first reported autonomous AI C2 implant Cisco Talos
- 2Primary source · September 22, 2026Introducing CAIRN: Frontier tracking for AI-integrated malware Cisco Talos
- 3Primary source · September 2026Cognitive-Artifact-Intelligence-Research-Network (CAIRN) Cisco Talos on GitHub
- 4Research · September 22, 2026New ClosedQuorum Windows malware uses AI for attack decisions BleepingComputer
- 5Research · September 23, 2026This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move The Hacker News
- 6Research · September 22, 2026Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions The Register
- 7Research · February 19, 2026PromptSpy ushers in the era of Android threats using GenAI ESET WeLiveSecurity
- 8Research · July 18, 2025CERT-UA Discovers LAMEHUG Malware Linked to APT28, Using LLM for Phishing Campaign The Hacker News
- 9Research · August 25, 2026The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution Palo Alto Networks Unit 42
We read both Talos reports and its research files, then compared BleepingComputer, The Hacker News, and The Register. All technical findings come from Talos, and we found no independent analysis of the samples. We checked earlier AI-malware cases with ESET, CERT-UA reporting, and Unit 42.