Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI-Driven Windows Malware Uses Voting System

AI-Driven Windows Malware Uses Voting System

Posted on September 23, 2026 By CWS

A newly identified Windows malware named CLOSEDQUORUM has been engineered to execute its operations through a consensus of up to four AI models, diverging from the traditional method of receiving commands from an attacker’s server, according to Cisco Talos. This innovative approach was reported on September 22, highlighting a shift in how malware might operate in the future.

Though the malware is capable of extracting Windows credentials, browser passwords, and cryptocurrency wallet data, it has not yet been observed executing these functions from start to finish. Its public version is currently non-functional, as confirmed by Talos’s analysis, which dates back to June 17, 2026. The discovery came alongside the release of CAIRN, an open-source tool designed to detect AI-utilizing malware.

AI Models Taking Control

Instead of relying on a command-and-control (C2) server, CLOSEDQUORUM queries up to four AI services—DeepSeek, Qwen, Mistral, and Google Gemini—to determine its next steps. The malware transmits basic system information, including the computer’s name, Windows version, and administrator status, alongside a list of predefined actions for the AI models to select.

The models choose among actions such as steal, inject, persist, and move, although the ‘move’ option currently lacks functionality. Each AI model must respond in a specific format, and the malware proceeds with the action that receives the majority vote. If no valid responses are received, the malware waits and retries, avoiding default actions.

Operational Mechanics and Limitations

While the malware operates autonomously via AI decisions, the attacker remains informed of each step through a Discord channel. Before executing any action, CLOSEDQUORUM posts its decisions and the corresponding AI rationale to the channel using a Discord webhook. This is also where the stolen data is sent.

Functionality depends on API keys and an active Discord webhook, which are incorporated during the malware’s compilation. Test versions showed placeholders for these credentials, rendering the public version unable to access AI services or transmit data effectively.

Defensive Measures and Detection

Talos advises security professionals to focus on behavioral analysis rather than blocking specific AI domains, as legitimate applications may also communicate with these services. Indicators of compromise include unusual AI service traffic, multiple AI provider requests, LSASS access, and process injections.

The malware uses specific techniques like Early Bird APC injection and process hollowing for code execution, while persistence is achieved through Windows Registry modifications and WMI event subscriptions. Encrypted stolen files are fragmented and uploaded to Discord in small increments.

Talos has issued a Snort rule, 1:66984, to detect prompts sent to AI services, though it requires TLS inspection for effectiveness. YARA rules are also available, primarily for scanning file data.

In summary, CLOSEDQUORUM represents a novel use of AI in malware, underscoring potential vulnerabilities and challenges in cybersecurity. Vigilance and adaptation in defense strategies are crucial as these threats evolve.

The Hacker News Tags:AI malware, AI models, API keys, CLOSEDQUORUM, cyber threats, Cybersecurity, Discord channel, malware analysis, Talos, Windows security

Post navigation

Previous Post: Critical Vulnerability in Next.js Allows RCE via SVG
Next Post: Outerlimit Secures $16M to Curb AI Agent Risks

Related Posts

New Android Malware Wave Hits Banking via NFC Relay Fraud, Call Hijacking, and Root Exploits New Android Malware Wave Hits Banking via NFC Relay Fraud, Call Hijacking, and Root Exploits The Hacker News
Unitree G1 EDU Robots Face Critical Security Vulnerabilities Unitree G1 EDU Robots Face Critical Security Vulnerabilities The Hacker News
Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks The Hacker News
Preparing for Quantum Security: A Crucial Webinar Preparing for Quantum Security: A Crucial Webinar The Hacker News
REVSTEALER Modules Disable Security to Run Crypto Miner REVSTEALER Modules Disable Security to Run Crypto Miner The Hacker News
Europol Dismantles 0 Million Cryptocurrency Fraud Network, Arrests Five Suspects Europol Dismantles $540 Million Cryptocurrency Fraud Network, Arrests Five Suspects The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical cPanel Security Flaws Threaten User Data
  • Outerlimit Secures $16M to Curb AI Agent Risks
  • AI-Driven Windows Malware Uses Voting System
  • Critical Vulnerability in Next.js Allows RCE via SVG
  • Exploring AI Threats: Potential Doomsday Scenarios

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical cPanel Security Flaws Threaten User Data
  • Outerlimit Secures $16M to Curb AI Agent Risks
  • AI-Driven Windows Malware Uses Voting System
  • Critical Vulnerability in Next.js Allows RCE via SVG
  • Exploring AI Threats: Potential Doomsday Scenarios

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark