Security Researchers Find Harmful Software That Asks Four AI Chatbots to Vote on Its Next Move
Researchers at Cisco, a major internet equipment company, describe a piece of harmful software for Windows computers that doesn't wait for a criminal to give it orders. Once it's inside a computer, it asks four AI chatbots what to do and goes with the majority. The copy they found was not yet working, and it hasn't been seen attacking anyone, but they say it shows where attacks are heading.
Researchers at Talos, the security research group at Cisco, published a report today on a piece of harmful software they call CLOSEDQUORUM. They describe it as the first publicly documented program of its kind for Windows computers.
Normally, once criminals sneak harmful software onto a computer, a person on the other end has to tell it what to do next: look for passwords, dig in deeper, hide. That takes a human's time and attention. CLOSEDQUORUM hands those decisions to AI instead. It sends its question to four different commercial AI chatbots, DeepSeek, Qwen, Mistral and Google's Gemini, counts their answers, and does whatever most of them pick. Its goals are to steal Windows login details, passwords saved in web browsers like Chrome, Edge and Firefox, and cryptocurrency wallets.
"Human operators are bound by attention, working hours, and cognitive load," said Ryan Fetterman, a Talos analyst, quoted by the technology news site The Register. "An AI system capable of executing a phase of the attack chain can continue when the operator is no longer watching."
There are important limits to what was found. The copy the researchers examined does not work as it stands: the passwords it would need to reach the AI services were placeholders, apparently to be filled in for each criminal who uses it. And Talos says no attacks on real victims have been confirmed. Clues inside the program tie its maker to online criminal forums about stolen credit cards going back to 2025.
Talos's worry is the direction, not this one program. Each step of a break-in that can be handed from a person to an AI, it says, lets attackers do more, faster, with fewer people. Its advice to companies is to watch for an ordinary Windows program that suddenly starts talking to AI services while also behaving like known harmful software.
Sources
- Cisco Talos — The Closed Quorum: inside the first reported autonomous AI command-and-control implantblog.talosintelligence.com · primary
- The Register — CLOSEDQUORUM malware uses AI models to choose its next stepstheregister.com