Black-and-white illustration of a human skull wearing an ornate crown.

CLOSEDQUORUM: New AI Tech Threatens Fresh Danger

LATEST


Sign up for honest takes & news that matters

Get the latest stories, interviews and independent takes delivered straight to your inbox.

CLOSEDQUORUM, a malware system, is asking AI models for advice on what it should do next.

Security researchers at Cisco Talos — Cisco’s threat-intelligence and cybersecurity research arm — have uncovered new behaviour from a new type of malware called CLOSEDQUORUM. The new software consults four different AI models, including Google Google’s Gemini, DeepSeek, Mistral and Alibaba’s Qwen, conferring with each system like a council.

How Cisco Talos' CAIRN works.

Discovered and Aided by Google

The malware was discovered through research conducted by Cisco Talos using VirusTotal, Google’s cybersecurity service, which collects suspicious and submitted files — where researchers found a sample listed within its database. Cisco found not one, but several development builds, suggesting the malware had undergone continued development. Its files contained placeholder API credentials and a dummy Discord webhook, meaning the version analysed wasn’t fully configured for live use. Working credentials would be needed for it to communicate with each artificial intelligence model.

It does this to determine what action it should take next by submitting potential actions to the models, then using their responses in a voting system to decide what it should do. If the votes are tied, DeepSeek’s vote overrides the others.

Researcher Ryan Fetterman, who authored the Cisco Talos report, writes: “A third dimension has received less attention in the malware space: effort displacement. This is not merely augmenting what an operator can accomplish in a session but transferring an entire phase of the attack from the operator to the system. Effort displacement compounds the effects of speed and scale because the human-in-the-loop is no longer the bottleneck.”

High-Risk Data Theft

CLOSEDQUORUM is capable of intrusive data theft and can scan for and obtain Windows credentials, cryptocurrency wallet data and browser passwords, all while injecting its own code into computational frameworks.

The dangers are particularly difficult to circumvent, as without a human agent continually directing it, the malware can act with the aid of four AI models, using each AI system as part of its core architecture.

While CLOSEDQUORUM has not yet been confirmed to have affected anyone, it’s a showcase of the vastness of virus and malware communities.

Leave a Reply

Discover more from Stanisland Magazine

Subscribe now to keep reading and get access to the full archive.

Continue reading