Windows Malware Utilizes AI Voting Mechanism for Command Decisions
A newly discovered Windows malware, CLOSEDQUORUM, employs up to four AI models to autonomously decide its actions, such as credential theft and code injection, marking the first documented case of AI-driven command decisions in malware. The malware relies on external AI services and Discord for coordination, introducing new attack vectors and dependencies on third-party infrastructure.
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22.
The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
*** END OF TRANSMISSION ***