This Windows malware puts its next move to a vote of four chatbots
Four AI models vote on what happens next. The action with the most votes is the one the malware carries out, and when the vote ties, DeepSeek decides.
Cisco Talos published the analysis on 22 September. The sample is called CLOSEDQUORUM, a 16.4MB Windows program written in Go, and researcher Ryan Fetterman describes it as the first publicly documented Windows implant to hand its tactical decisions to a panel of commercial chatbots. A component named ModelOrchestrator puts the same structured question to DeepSeek, Qwen, Mistral and Google Gemini and insists on a machine-readable answer rather than prose. The choices on the ballot are the standard criminal menu: pull credentials out of LSASS, raid saved browser passwords and cryptocurrency wallets, inject code into a running process, set up persistence, or move sideways to another machine. Whatever it takes leaves through a Discord webhook.
Now the honest caveat. Talos has not seen this used against anybody. The copy it examined shipped with dummy API keys and placeholder credentials, which is what an unfinished build looks like, though artifacts in the code tie its author to carding forum posts from 2025. Talos also released the tool that found it, an open-source framework called CAIRN that hunts for the traces AI-enabled malware leaves behind, such as embedded prompts and calls out to model providers.
So this is a prototype, not an emergency. What it changes is the arithmetic. Ordinary malware needs a criminal awake at a keyboard deciding what to do with each machine it lands on, and that is a real limit on how many machines one person can work. This one does not, and its decisions do not need to be clever, only cheap and endless. The defence is unchanged, because it still has to get onto your PC first, almost always as something you were talked into running. Tendvane's safety check goes through what is installed and flags the programs that turned up without an invitation.