This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
Summary
CLOSEDQUORUM is a Windows malware that uses a voting system from up to four AI models (DeepSeek, Qwen, Mistral, and Google Gemini) to decide what malicious actions to perform, such as stealing passwords and crypto wallet data, instead of taking orders from a traditional command-and-control server. The malware sends information about the victim's computer to the AI models and executes whatever action receives the most votes, with results posted to Discord. While Talos researchers discovered this malware and the public version does not currently work due to missing API keys and placeholder values, it represents an early example of attackers delegating attack decisions to AI services.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html
First tracked: September 23, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 85%