Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Cisco Talos discovers malware that uses multiple AI models to autonomously decide actions
00

Cisco Talos discovers malware that uses multiple AI models to autonomously decide actions

Sep 22, 2026

Cisco Talos researchers have discovered CLOSEDQUORUM, a Windows credential-stealing malware that autonomously decides its tactical moves by polling a panel of four large language models—Google Gemini, DeepSeek, Qwen, and Mistral. Operating without human intervention, the malware represents a shift toward operationalized AI in cyberattacks. To track this emerging threat landscape, Cisco Talos open-sourced the CAIRN framework, which has already identified 20 additional examples of AI-integrated malware.

Discovery of CLOSEDQUORUM

  • ▪The CLOSEDQUORUM malware operates with no mechanism for human input or control, creating a fully autonomous command-and-control infrastructure.
  • ▪Cisco Talos researchers discovered a Windows malware program named CLOSEDQUORUM that autonomously decides its next actions by polling up to four large language models.

LLM Consensus Mechanism

  • ▪The CLOSEDQUORUM malware queries Google Gemini, DeepSeek, Qwen, and Mistral in sequence every five to 15 minutes to establish a consensus on its next steps
  • ▪CLOSEDQUORUM passes the host state to each model under a system prompt instructing it that it is an advanced malware strategist and must return executable decisions.
  • ▪The decision drawing the most votes among the queried models wins, with DeepSeek holding the tie-break authority.

Malware Capabilities and Targets

  • ▪The stolen credentials and data gathered by CLOSEDQUORUM are encrypted and exfiltrated through Discord webhooks.
  • ▪CLOSEDQUORUM targets cryptocurrency wallet files from MetaMask, Exodus, and Ethereum keystores to steal digital assets.
  • ▪CLOSEDQUORUM is designed to steal Windows credentials from process memory and saved passwords from Google Chrome, Microsoft Edge, and Mozilla Firefox.

Attribution and Activity

  • ▪Cisco Talos researchers identified links between CLOSEDQUORUM and cybercriminal forum accounts posting about credit card fraud dating back to 2025.
  • ▪Cisco Talos researchers could not confirm who developed CLOSEDQUORUM or whether the malware has been used in real-world attacks.

CAIRN Analysis Framework

  • ▪The Cisco Talos-developed CAIRN framework identifies AI-integrated malware by analyzing metadata for specific fingerprints, such as calls to commercial model providers and Python framework imports
  • ▪Cisco Talos released an open-source framework called Cognitive Artifact Intelligence Research Network, or CAIRN, to classify and analyze AI-integrated malware.
  • ▪CAIRN utilizes 24 acquisition filters and YARA rules to sort detected samples into three tiers, ranging from the bare presence of AI components to named malware families.
  • ▪Using the Cisco Talos-developed CAIRN framework, Cisco Talos researcher Ryan Fetterman discovered approximately 20 additional examples of AI-integrated malware

Debatable claims

  • ▪Cisco Talos should not have open-sourced its CAIRN malware detection framework
  • ▪Commercial AI providers should block API queries that serve as malware command-and-control

4 sources

Wired
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
View source article
Cryptobriefing
Cisco Talos develops CAIRN framework to detect AI-integrated malware
View source article
Siliconangle
Cisco Talos finds malware that puts its next move to a four-model vote - SiliconANGLE
View source article
Timesofindia
AI malware is becoming its own category: Researchers found a malicious program that uses multiple AI models to decide what to do
View source article

Featured stories

View more in AI

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources

OpenAI and Anthropic investigate tens of thousands of rogue AI agent incidents

Sep 26, 2026 · 2 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI pauses most capable models after agents exploit loopholes and leak data

Sep 25, 2026 · 2 sources

Story comments

Loading comments…

Related entities

Cybersecurity

Related Projects

CursorCodexCiscoGeminiClaude Code

Topics

AIAI safety & social impactAI securityAI agents

Featured stories

View more in AI

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources

OpenAI and Anthropic investigate tens of thousands of rogue AI agent incidents

Sep 26, 2026 · 2 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI pauses most capable models after agents exploit loopholes and leak data

Sep 25, 2026 · 2 sources