Four AI Chatbots Are Running a Malware Operation Without Human Commands

Cisco Talos researchers found the Windows implant querying DeepSeek, Qwen, Mistral and Gemini to vote on post-compromise actions autonomously

Rex Edison Avatar
Rex Edison Avatar

By

Image: Cisco Talos

Key Takeaways

Key Takeaways

  • CLOSEDQUORUM delegates attack decisions to four AI models using a plurality vote system.
  • Cisco Talos released CAIRN, uncovering roughly 20 AI-integrated malware samples beyond prior documented cases.
  • Monitor outbound connections to AI provider endpoints, as malware can use legitimate domains as cover.

Cisco Talos has documented a Windows implant that delegates tactical decisions to a panel of AI models rather than waiting for commands from a human operator. Named CLOSEDQUORUM, the malware can query up to four large language models to select its next attack action, with no built-in channel requiring continued human tasking after deployment. Talos describes it, to its knowledge, as the first publicly documented Windows implant to use this approach for tactical command and control.

No confirmed victims have been identified. The creator is unknown.

How CLOSEDQUORUM Makes Its Decisions

The implant uses a structured voting process across multiple AI providers to choose its next post-compromise action from a predefined set of capabilities.

The malware sends information about a compromised host to up to four commercial AI providers: DeepSeek, Qwen, Mistral and Google Gemini.

Each model returns a structured response, and CLOSEDQUORUM executes whichever action wins the plurality vote. When votes tie, a fixed preference order resolves the deadlock: DeepSeek first, then Qwen, Mistral and Gemini last.

The models are not generating open-ended attack plans. They select from a constrained set of predefined post-compromise actions built into the malware.

CLOSEDQUORUM targets Windows credentials, browser-stored passwords and cryptocurrency wallet data. The multi-provider design also creates redundancy: if one AI service is unavailable, the implant can continue querying the remaining models.

“CLOSEDQUORUM, to our knowledge, is the first publicly documented Windows implant to apply this model to tactical command and control,” the Cisco Talos research team wrote in its disclosure.

How Researchers Found It, and What Comes Next

Talos released an open-source toolkit called CAIRN specifically to detect, classify and track malware that integrates AI services.

CAIRN, the Cognitive Artifact Intelligence Research Network, scans malware samples for technical traces of AI integration: model-provider endpoints, prompt structures, framework references and similar metadata.

“The core idea is that AI integration has these vestiges, like fingerprints, that are left behind,” Cisco Talos researcher Ryan Fetterman told Wired (specific article URL unavailable at time of publication).

During development and testing, CAIRN uncovered roughly 20 additional AI-integrated malware samples. That total exceeds the approximately nine families previously documented publicly. Fetterman characterized the field as still largely experimental but more diverse than prior reporting had suggested.

CLOSEDQUORUM represents a meaningful step beyond earlier examples. LAMEHUG, a surveillance app linked by Ukraine’s CERT-UA to a July 2025 phishing campaign, queried a Qwen coding model through a Hugging Face API to retrieve commands. CLOSEDQUORUM differs in a significant way: it does not require continued human tasking for each post-compromise decision, placing the AI models inside the malware’s own decision cycle rather than keeping them as tools in an attacker’s workflow.

That distinction matters. Earlier AI-integrated malware varied in function, but CLOSEDQUORUM delegates tactical action selection to a model panel without requiring a human to issue each command.

What This Means for Windows Users

CLOSEDQUORUM has not been confirmed as an active campaign, but its design points to a threat category that security teams should begin monitoring now.

Treat this as an early signal, not an alarm. Talos analyzed a sample; no in-the-wild deployment has been confirmed.

The multi-provider design does suggest a direction worth tracking. Malware that queries redundant AI services could prove harder to disrupt than malware dependent on a single command server. Security teams may need to monitor suspicious outbound connections to AI provider endpoints alongside traditional command-and-control infrastructure, since legitimate AI provider domains can serve as cover for malicious queries. For individual users, the documented targets point toward concrete precautions:

  • Keep Windows updated.
  • Use a dedicated password manager rather than browser-stored credentials.
  • Protect cryptocurrency wallets with hardware keys where possible.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →