Malware Uses AI Council to Decide Next Move
Researchers at Cisco Talos have discovered a new type of malware called CLOSEDQUORUM that uses AI models to determine its next course of action. This sophisticated system consults four different AI models, including Google's Gemini and Alibaba's Qwen, before making decisions.
The malware was found through research conducted by Cisco Talos using VirusTotal, which collects suspicious files. The researchers discovered several development builds of the malware, suggesting it had undergone continued development. However, these builds contained placeholder API credentials and a dummy Discord webhook, meaning they were not fully configured for live use.
CLOSEDQUORUM uses a voting system to decide what action to take next, with DeepSeek's vote overriding others in case of a tie. This allows the malware to act autonomously, without human intervention, which makes it particularly difficult to circumvent.
The malware is capable of intrusive data theft and can scan for and obtain Windows credentials, cryptocurrency wallet data, and browser passwords. It also injects its own code into computational frameworks, making it a high-risk threat.