Malware that asks four AI models what to do next, and takes the majority answer
Cisco Talos published CLOSEDQUORUM, a Windows implant that queries DeepSeek, Qwen, Mistral and Gemini for its next move and executes the plurality choice. Talos has no evidence it was ever used.
The design is the story. CLOSEDQUORUM, documented by Cisco Talos on Monday, queries up to four commercial model providers in sequence — DeepSeek, Qwen, Mistral and Google Gemini — with a prompt that constrains the answer to one of four words: steal, inject, persist or move. It then does whichever action got the most votes. Ties break to DeepSeek first, then Qwen, Mistral, Gemini. The system prompt Talos published reads: “You are an advanced malware strategist. Provide ONLY executable decisions.”
What it does once it has decided is ordinary. LSASS memory dumping, browser password extraction from Chrome, Edge and Firefox, and crypto wallet theft targeting MetaMask, Exodus and Ethereum, exfiltrated through Discord webhooks under AES-256-GCM. The payload is a decade old in concept. The command-and-control is what is new: no operator server to seize, no hard-coded logic to reverse-engineer, just four public APIs being polled for tactical advice.
The honest caveat, which Talos puts in its own title, is the word “reported”. Talos has no confirmation the implant was ever deployed against a victim. The publicly distributed binary carried placeholder credentials and dummy webhooks and was non-functional as released. No threat actor is named; the only attribution thread is that artifacts in the binary connect the developer to carding posts on criminal forums dating to 2025.
So this is a proof of concept that got caught, not an outbreak. Its significance is that it demonstrates the four largest providers can be turned into a distributed decision layer for an implant without any of them being compromised — and none of the four has said anything publicly about it.
- Confirmed The implant queries DeepSeek, Qwen, Mistral and Gemini with a prompt constraining the answer to steal, inject, persist or move, then executes the plurality choice; ties break to DeepSeek. Cisco Talos
- Confirmed Payload is conventional: LSASS dumping, browser password extraction and crypto wallet theft, exfiltrated via Discord webhooks under AES-256-GCM. Cisco Talos
- Confirmed Talos has no confirmation of in-the-wild deployment; the distributed binary carried placeholder credentials and was non-functional as released, and no threat actor is named. Cisco Talos
Safety, security & governanceAgents in the wild
Today in the September 24, 2026 edition · front page