Ai-powered malware targets windows 11, uses autonomous decision-making
On September 22, the Cisco Talos security team disclosed an AI-based malware named ClosedQuorum, which targets Windows 11 systems. This malware, built using Go, operates autonomously after infiltrating a device, using AI models like Google Gemini, DeepSeek, Qwen, and Mistral to make decisions. Talos noted that ClosedQuorum can steal browser credentials, extract cryptocurrency data, and spread to other devices without human intervention. The malware employs a 'voting system' to determine its next actions, marking it as the first publicly documented Windows implant program that delegates tactical command and control (C2) decisions to AI models. Talos emphasized that this trend increases the speed and scalability of malicious operations, allowing attackers to penetrate more devices at a lower cost. The team urged defenders to monitor for AI-driven, autonomous decision-making malware and advised users to update patches, enable multi-factor authentication, and avoid suspicious files and links.
ClosedQuorum's autonomy means it can continue attacks even if the command server goes offline, presenting new challenges for traditional security defenses that rely on identifying C2 beacons through traffic patterns. Talos has shared technical analysis and warned of the growing threat posed by such AI-driven malware, highlighting the need for updated defensive strategies.