When the malware starts making its own decisions

You know how Netflix asks what you want to watch, then serves up whatever its algorithm thinks you'll like anyway? Now imagine malware doing the same thing — except instead of one algorithm, it's polling four different AIs. And instead of picking your next show, they're voting on its next move: steal your saved passwords and crypto wallets, hide inside a legitimate program, or dig in so it survives a reboot.

That's what Cisco Talos just documented. On September 22, its researchers disclosed CLOSEDQUORUM, a strain of Windows malware that doesn't call home to a hacker's server for instructions. Every 5 to 15 minutes, it asks four commercial AI models — DeepSeek, Qwen, Mistral, and Google's Gemini — what to do. Whatever the majority says, it does. If there's a tie, DeepSeek breaks it.

No command server. No human issuing orders. The attacker's only job is to get it onto your machine, then wait for your stolen passwords to show up, encrypted, in a Discord channel. One caveat: Talos hasn't confirmed it's been used against real victims yet — the sample they found shipped with dummy keys. But its developer is tied to criminal carding forums going back to 2025, and the whole thing looks built to sell.

What's actually happening inside your computer

Traditional malware works like a remote-controlled car. An attacker connects to it through a server they control, sends commands, and waits for results. Defenders learned to spot this: they watch for strange network traffic, block connections to known attacker servers, and cut the signal.

CLOSEDQUORUM doesn't work that way. Once it's on your machine, it takes a quick inventory — the computer's name, which version of Windows it's running, how many processors it has, and whether it has administrator rights. Then it sends that snapshot to four AI models with a blunt instruction: you are a malware strategist, give me a decision. Each model has to pick from a short menu — steal passwords and crypto wallets, hide inside another program, or dig in so it survives a reboot — and explain why. The malware tallies the votes. Majority rules.

This isn't sci-fi. It's using APIs — the same interfaces that let your phone's weather app talk to a weather service. Except here, the malware is buying attack advice from DeepSeek, Alibaba's Qwen, Mistral, and Google's Gemini, and to those services it looks like just another paying customer. The designer even planned for one of them to refuse or glitch: with four models in the room, one "no" doesn't stop the vote.

That's what makes this different. For decades, defenders could take down the attacker's server and the malware went deaf. Here there's no server giving orders to take down — just four of the biggest AI platforms on the planet. The only thing the attacker still owns is the drop point: stolen passwords land, encrypted, in a Discord channel.

Here's the part that should make you uncomfortable: the same AI services companies are rolling out for productivity can now double as an attacker's brain, and blocking by domain alone won't save you. But this malware isn't invisible. A background Windows program quietly polling four AI companies — including two Chinese providers most US companies never use — and then talking to Discord is exactly the kind of pattern your security tools can catch, if someone tells them to look.

Why this is getting worse right now

This didn't come out of nowhere. In July 2025, Ukraine's cyber agency caught Russian military hackers using malware that asked an AI model to write its attack commands on the fly. Google later called it the first malware to query an AI model in the middle of a real attack. CLOSEDQUORUM takes the next step: the AI isn't just writing the commands anymore — a panel of four AIs is deciding what to do. Talos hasn't seen it used against real victims yet, but the blueprint is now public. Three things made it possible:

First, AI models got good enough to make tactical calls. They don't just summarize text anymore — given a situation and a short list of options, they'll pick one and explain why. That's exactly what malware needs once it's sitting on a machine with no one at the controls.

Second, API access became cheap and everywhere. Any developer — or attacker — can get keys to multiple AI providers quickly, including low-cost ones like DeepSeek and Qwen. Vendors do watch for abuse and shut accounts down when they catch it. That's why CLOSEDQUORUM asks four of them instead of one: lose a key, get a refusal, and the vote still happens.

Third, defenders got comfortable seeing AI traffic everywhere. A few years ago, unexpected API calls to an AI service might have raised flags. Now? Your HR system uses AI to screen resumes. Your security tools use AI to analyze logs. Your developers use AI to write code. A call to Google's Gemini from a laptop doesn't stand out. The question is whether anyone notices when that same laptop is also talking to DeepSeek and Qwen — on a timer, every few minutes, from a program nobody installed.

What to actually do about it

This is easier to defend than it sounds, because the AI is only the brain. The body is classic credential-theft tradecraft your tools already know how to catch. Here's what reduces your exposure:

1. Know what's supposed to talk to AI services. If you manage a network, catalog which applications and services are authorized to call external AI APIs. If a process you don't recognize is talking to DeepSeek, Qwen, Mistral, or Gemini, that's a signal — especially the first two, which most US companies have no reason to use.

2. Hunt the pattern, not the domain. Talos's guidance is behavioral. Look for AI-provider API traffic coming from an unexpected Windows executable (a browser tab is normal; a background process is not), similar requests hitting several providers in quick succession, and the same process or host also posting to a Discord webhook. Discord traffic from a server or a non-browser process has almost no legitimate business reason.

3. Watch for the old tells, too. LSASS access, injection into suspended processes, and new WMI persistence are what this malware does after the AI makes its call. Endpoint tools can already alert on them — make sure they do.

4. Lock down egress where it makes sense. If a server has no legitimate reason to reach an AI provider or Discord, deny it and allowlist the exceptions. Blocking domains alone won't stop a determined attacker, but it shrinks where this can operate.

5. Protect what it steals. This malware goes after saved browser passwords, credentials in Windows memory, and crypto wallets. Stop saving passwords in the browser, use a password manager and passkeys where you can, and keep crypto in a hardware wallet. On Windows machines, turn on LSA protection and Credential Guard.

6. Update your mental model. The delivery is still the usual — phishing, cracked software, a bad download. What's new is that nobody has to be behind the keyboard once it lands. The tradecraft is old. The decision-maker is new.

Have you checked what's calling out to AI services from your network?

Most people haven't. Most organizations haven't either. If you've looked — or if you've found something unexpected — I want to hear about it.

Identity Decoded publishes every week at identity-decoded.com

Reply

Avatar

or to participate