Military & Security

Cisco Talos finds malware that puts its next move to a four-model vote

· September 22, 2026
Cisco Talos finds malware that puts its next move to a four-model vote

What happened

Cisco’s Talos Threat Intelligence team uncovered a new type of malware named CLOSEDQUORUM that uses artificial intelligence to decide its next actions. Unlike typical malware relying on a command-and-control server for instructions, CLOSEDQUORUM autonomously selects its next move by voting among four AI models. The research came with an open-source toolkit designed to help operators detect AI-driven malware like this Windows credential stealer.

The risk

This malware bypasses traditional command centers, making it harder to track and shut down. Its AI-driven decision-making means it can adapt tactics dynamically, raising the bar for threat hunters who rely on predictable attack patterns. CLOSEDQUORUM’s approach could speed up malware evolution, allowing bad actors to evade defenses by changing behavior on the fly without external commands.

Why it matters

Operations teams face a new challenge: dealing with malware that thinks independently about its tactics. The usual strategy of cutting off centralized control points will not work here. This development pressures cybersecurity tools and defenders to anticipate adversaries that embed their own AI logic locally, forcing faster detection methods focused on behavioral anomalies inside endpoints.

Who should pay attention

Security teams, endpoint protection vendors, and incident responders must factor AI-driven malware control into their threat models. Builders of detection tools will need to consider how to identify AI decision processes within malicious code. Organizations running Windows infrastructure should be alert to credential-stealer variants that can hide commands internally.

What to watch next

Track the evolution of open-source AI malware tooling and how defenders adopt Talos’s hunting kit. Watch for new AI models added to malware voting systems that can increase complexity and autonomy. Expect tighter collaboration between threat intelligence teams and endpoint security vendors to pinpoint AI-led attack indicators before they escalate.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.