Malware Takes Orders From Four AI Models
24SEP
Cisco Talos pulled apart a Windows implant with no operator behind it. Each step is decided by a majority of DeepSeek, Qwen, Mistral and Gemini. It has not been seen attacking anyone yet.
The sample is called CLOSEDQUORUM. Sixteen megabytes of Go. Its system prompt reads: you are an advanced malware strategist, provide only executable decisions. The models vote. DeepSeek breaks ties.
Choices on the ballot: steal, inject, persist, move sideways. Targets include LSASS credentials, browser passwords, and MetaMask, Exodus and Ethereum wallets. Loot leaves through a Discord webhook under AES-256-GCM.
Talos found dummy API keys in the public build, so this is a prototype, not a campaign. The author's handle traces back to carding forum posts. Talos shipped CAIRN, an open-source tracker for AI-driven malware, the same day.