Malware That Lets AI Models Vote on Attacks—What You Need to Know

·
Listen to this article~4 min
Malware That Lets AI Models Vote on Attacks—What You Need to Know

A new Windows malware called CLOSEDQUORUM uses up to four AI models to vote on stealing credentials, browser passwords, and crypto wallets. Here's what you need to know.

Imagine malware that doesn't just follow orders from a human attacker. Instead, it asks up to four AI models to vote on what to do next. That's exactly what Cisco Talos researchers found in a new Windows malware they call CLOSEDQUORUM. Reported on September 22, this discovery shows how AI could change the game in cyberattacks. ### How CLOSEDQUORUM Works At its core, CLOSEDQUORUM is a malware that connects to multiple AI models—up to four—and lets them decide the next move. The models vote on actions like stealing Windows credentials, saved browser passwords, or crypto wallet data. It's like having a committee of AI advisors for a cyber heist. But here's the catch: Talos hasn't seen this setup work from start to finish. The public version of the malware doesn't function as intended. So while the idea is scary, it's not yet a fully operational threat. ### Why This Matters for Your Security Even if this specific malware isn't working yet, it signals a shift. Attackers are experimenting with AI to automate and optimize their attacks. If they succeed, it could mean faster, more adaptive malware that's harder to stop. - **Credential theft**: The AI models could choose to steal your Windows login details. - **Browser passwords**: Saved passwords in your browser are a prime target. - **Crypto wallets**: If you hold cryptocurrency, the malware might go after your wallet data. ### What You Can Do to Stay Safe You don't need to panic, but you should stay vigilant. Here are some practical steps: - Keep your operating system and software updated. Patches fix vulnerabilities that malware exploits. - Use a reputable antivirus and keep it updated. It can catch known threats. - Enable multi-factor authentication (MFA) wherever possible. Even if credentials are stolen, MFA adds a barrier. - Be cautious with downloads and email attachments. Don't click on suspicious links. - Consider using a password manager with strong encryption. It's safer than saving passwords in your browser. ### The Bigger Picture: AI in Cyberattacks This isn't the first time AI has been linked to cyberattacks. But CLOSEDQUORUM is a notable example of AI being used for decision-making in malware. As AI models become more accessible, we might see more experiments like this. However, it's important to note that the public version of CLOSEDQUORUM doesn't work as intended. That could mean the attackers are still refining it, or it could be a proof of concept. Either way, it's a reminder that the threat landscape is always evolving. > "The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data," Talos said. But they haven't seen it work end-to-end. ### Final Thoughts While CLOSEDQUORUM isn't a working threat yet, it's a wake-up call. AI is not just for good—it can be misused. Stay informed, keep your defenses up, and don't underestimate the creativity of attackers. If you're in the US, make sure your cybersecurity practices are up to date. The bad guys are always looking for new ways in, and now they're getting help from AI. Remember, the best defense is a good offense. Stay proactive, and you'll be better prepared for whatever comes next.