EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 65/100

Il malware Windows CLOSEDQUORUM utilizza fino a quattro modelli AI per decidere le azioni da compiere, come rubare credenziali e dati criptovaluta. Non è stato osservato in esecuzione completa. Il malware richiede API e un webhook di Discord per funzionare. Talos ha rilevato il malware tramite CAIRN e lo ha pubblicato come primo esempio di malware che delega decisioni C2 agli AI.

Why it matters

Per le PMI italiane, il rischio è la compromissione di credenziali e dati sensibili tramite un approccio innovativo e difficile da rilevare. La dipendenza da servizi esterni e la mancanza di patch rendono il malware un potenziale minaccia non trascurabile.

Potential operational benefits

  • Riduzione della superficie esposta a servizi esterni
  • Miglioramento della rilevazione di comportamenti anomali
  • Minimizzazione del rischio di compromissione di credenziali
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsMonitoraggio / SIEMFirewall NGFW / IPSEDR / XDRPatch managementSegmentazione di rete
AudienceSOCIT
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
23/09/2026 16:17
MITRE ATT&CK
T1486, T1059.001, T1078
Open the original source