Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
Every few minutes, a Windows program sends a short description of the computer it is running on to DeepSeek, then to Qwen, then to Mistral, then to Google Gemini. Its question is the same each time: steal, inject, or persist? It counts the answers, picks whichever got the most votes, and carries it out. If the vote is tied, DeepSeek decides.
Cisco Talos published its analysis of this implant, which it calls CLOSEDQUORUM, on 22 September 2026. The code itself is unremarkable credential-theft tooling. What is new is the part that is missing: there is no attacker sitting behind it, and no attacker-owned server for defenders to find. The decisions a human operator used to make are rented, by the query, from the same AI services your own staff use.
Talos researcher Ryan Fetterman describes CLOSEDQUORUM as, to the team's knowledge, the first publicly documented Windows implant to hand its command and control to a panel of commercial large language models. Command and control, usually shortened to C2, is the channel through which an attacker tells malware on an infected machine what to do next. Normally that channel ends at a server the attacker runs, with a domain name and an IP address, and those are exactly what threat intelligence feeds publish and firewalls block. CLOSEDQUORUM replaces that server with the public APIs (the programmatic interfaces software uses to query an AI model) of four providers that thousands of legitimate applications call every day.
The loop is simple once you see it. On start-up the malware records the hostname, Windows version, processor count and whether it has administrator rights. It waits five minutes, then wakes at random intervals of 5 to 15 minutes. Each time, it sends that profile to each model with a system prompt that begins "You are an advanced malware strategist." The models are not allowed to answer freely: the reply must be a structured JSON object naming one action from a short menu, or it is thrown away. "Steal" dumps the memory of LSASS (the Windows process that holds login credentials), copies saved passwords from Chrome, Edge and Firefox, and lifts MetaMask, Exodus and Ethereum wallet files. "Inject" hides code inside another, legitimate process. "Persist" plants the malware in the registry, a scheduled task and a WMI event subscription, all with Windows Update-style names. Stolen data leaves encrypted, in small chunks, for a Discord webhook the operator reads.
Nobody has lost money to CLOSEDQUORUM yet, as far as anyone can show. The harm on offer is the ordinary kind: domain passwords, browser logins and crypto wallets from every machine it reaches, delivered to a buyer who never has to log in or watch. Talos calls this effort displacement. AI has so far made attackers faster and more prolific, but a person still steered each intrusion and still had to sleep. Here a whole phase of the attack runs while the operator is offline, and the next logical step is the "move" option that is already stubbed out.
For your security team the uncomfortable change is in the blocklist. A decade of detection has leaned on the fact that malware must phone home somewhere unusual. This one phones api.deepseek.com and api.mistral.ai, destinations an engineering laptop may legitimately reach several times an hour. So the useful question for Monday is not whether you block DeepSeek. It is whether you could tell which executable on a given workstation is talking to AI providers at all, and whether anything would flag an unsigned program that queries three of them within a minute and then reads LSASS memory. Talos stresses that the dependence on commercial services is also the weak point: refusals, rate limits and malformed answers stall the implant, and the providers can see the prompts. That puts a share of the defence in the hands of the AI companies, whose abuse monitoring now works as part of everyone's perimeter.
Talos found the sample with CAIRN, an open-source toolkit released the same day that searches malware metadata for embedded prompts and AI endpoints. It has been tracking this class since July 2025, when Ukraine's CERT-UA reported LAMEHUG, the earliest known AI-integrated malware seen in the wild. Fourteen months later the model is no longer drafting a command for a human to review. It is choosing the attack.
CLOSEDQUORUM is crude, unfinished and possibly never used. Keep it in mind anyway, because it proves the architecture works with off-the-shelf models and ordinary API keys: an attacker can now sell a program that makes its own tactical decisions and needs no infrastructure of its own. The question to bring to your next security review is a narrow one. If a program on one of your laptops started asking four AI models how best to rob it, which log would show it, and who reads that log?

