Autonomous AI Malware Emerges as Cyber Threats Take a New Turn
Cisco Talos researchers have identified a new malware framework called ClosedQuorum, which represents a major shift in cyber threats. Unlike traditional human-operated command-and-control (C2) servers, ClosedQuorum uses an autonomous, multi-AI voting system to make tactical decisions during post-compromise activity.
The name ClosedQuorum reflects the architecture, where up to four LLM providers - DeepSeek, Qwen, Mistral, and Google Gemini - are queried in sequence. Their independent verdicts are tallied, and the binary acts based on their judgment. A majority decision is used to select its next action.
ClosedQuorum has several available capabilities, including credential and cryptocurrency-wallet theft, process injection, and persistence. This creates an architecture where multiple AI models effectively act as a decision-making layer between the malware and the compromised system.