This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
- ID
- 27763
- Status
- summarized
- Published
- 23 Sep 2026, 10:17 PM
- Fetched
- 24 Sep 2026, 12:05 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 24 Sep 2026, 12:10 AM
- Tags
- Audience
- developersai_agent_usersai_ml_learners
What happened
Cisco Talos disclosed a Windows malware called CLOSEDQUORUM that polls up to four commercial AI models (DeepSeek, Qwen, Mistral, Google Gemini) to vote on each action—steal, inject, persist, or move—instead of receiving commands from a C2 server. The public version doesn't work (placeholder API keys and webhook), and Talos hasn't observed it functioning end-to-end, but the code is at least three months old. Talos also released CAIRN, an open-source tool to detect malware that calls AI services.
Why it matters
If you build AI agents or use LLM APIs in production, this is an early blueprint for adversarial use of the same APIs—hardcoded keys, structured-output voting, and Discord as exfiltration channel. Grab CAIRN from Talos to scan your own environment for processes making unexpected calls to DeepSeek, Qwen, Mistral, or Gemini endpoints, and treat your API keys as malware-grade secrets worth rotating.
Discussion angle
The voting architecture is trivially reproducible by anyone with API keys—what does this mean for API providers' responsibility to detect abusive structured-output patterns, and should builders assume their agent frameworks could be repurposed this way?