A quorum of models
Cisco Talos published research on Tuesday describing CLOSEDQUORUM, a Windows implant that decides what to do next by asking commercial AI models rather than waiting for a human operator. Talos calls it the first publicly documented Windows implant to apply that model to tactical command and control.
The distinction matters. Malware that calls an AI service to write a phishing lure still takes its orders from a person. According to Talos, this one does not: the implant “does not require continued commands from a human operator or tasking from a dedicated, attacker-operated C2 server,” and the complete dynamic operation is delegated to the AI.
How the vote works
CLOSEDQUORUM queries up to four commercial model providers in sequence — DeepSeek, Alibaba’s Qwen, Mistral and Google’s Gemini — and asks each one what the implant should do next. Each provider effectively casts a vote, and the majority decides which action runs. Where the vote is split, Talos says DeepSeek holds tiebreaker priority.
The design has an obvious operational logic: no attacker-controlled server to seize, no single provider whose account suspension kills the campaign, and a decision path that changes between runs because the models do.

What it is built to steal
The implant’s capabilities are conventional credential theft. Talos describes LSASS memory dumping, extraction of saved passwords from Chrome, Edge and Firefox, and theft from cryptocurrency wallets including MetaMask, Exodus and Ethereum wallets. The novelty is not in what it takes but in who decides when to take it.
Not seen in the wild
This is a research find rather than an incident report, and Talos is explicit about the limits of what it knows. The company says it does not have confirmation of in-the-wild deployment. It tracked development builds over seven days, and says artefacts in the samples connect the developer to criminal forum activity dating back to 2025.
CLOSEDQUORUM surfaced through CAIRN, a research toolkit Talos released on the same day and describes as a project for hunting, classifying and tracking emerging AI-integrated malware. The tooling and the first finding were published together, which tells you how new the category is.

Why this is awkward to detect
Talos recommends defenders focus on behavioural characteristics rather than domain blocking — the usual response of adding the command server to a blocklist does not apply when the command server is four public APIs that ordinary software also calls.
Instead it points to correlated indicators: API traffic to multiple AI providers from one host, combined with behaviour such as accessing LSASS, injecting into suspended processes, or creating WMI persistence. Any one of those is noise. Together they are a signature.
What to watch
Two questions follow. The first is what the four named providers do about traffic of this shape, given that their abuse teams can see the pattern from their side of the API. The second is whether CLOSEDQUORUM, or something built on the same idea, turns up in an actual intrusion — at which point the industry stops arguing about whether the category is real.