Windows Malware Uses AI Models for Command-and-Control Decisions
Cisco Talos has discovered a Windows malware strain called CLOSEDQUORUM that uses four AI models to decide its next move. The malware, which steals credentials and cryptocurrency wallet data among other actions, is unique in delegating command-and-control decisions to artificial intelligence rather than human operators.
The implant queries up to four commercial large language model services - DeepSeek, Qwen, Mistral, and Google Gemini - and executes the action receiving the most votes from the models. If the vote is tied, DeepSeek's choice takes precedence.
Talos notes that this approach creates weaknesses for attackers since AI services can refuse requests or impose limits. Defenders are advised to monitor behavioral combinations rather than block AI provider domains.