Download Privacy Needle App

Type to search

Cybersecurity

Cisco Talos Discovers Autonomous AI Malware Using LLM Decision Panel

Share

Researchers at Cisco Talos have identified a novel malware architecture that uses a panel of large language models (LLMs) to automate the command-and-control (C2) phase of an attack entirely without human involvement.

The malware, named CLOSEDQUORUM, represents a shift from AI-augmented attacks to fully autonomous operations. By delegating decision-making to a “quorum” of AI models, the malware can execute complex attack chains without waiting for commands from a human operator.

Autonomous Decision-Making via LLM Panel

CLOSEDQUORUM operates by querying multiple LLMs in sequence to determine the optimal path for an intrusion. The system supports integrations with DeepSeek, Qwen, Mistral, and Google Gemini. To ensure the AI’s decisions are actionable, the malware constrains the models to respond using a specific JSON structure, which allows the outputs to be automatically converted into executable commands.

In the event of a disagreement between models, the malware follows a deterministic tie-breaking logic, prioritising responses from DeepSeek. This multi-model approach is designed to increase the success rate of the attack, ensuring that if one model hits a safety guardrail or fails to respond, the others can still reach a consensus.

Ryan Fetterman, a security and threat researcher at Cisco Talos, noted that this “credentials-as-a-service” model means a human attacker does not need to be online to run a campaign; they simply deploy the binary and let the LLM panel manage the attack. Because the system does not require a human in the loop, it avoids the limitations of human working hours and cognitive load.

Targeting Credentials and Crypto Wallets

The malware is a 64-bit Windows executable compiled in the Go programming language. It specifically targets high-value data, including:

  • Microsoft LSASS: Attempting to dump domain and local credentials from the Local Security Authority Subsystem Service (LSASS), which handles logins and security policies.
  • Browser Data: Extracting saved passwords from Google Chrome, Microsoft Edge, and Mozilla Firefox.
  • Cryptocurrency Assets: Searching for and extracting wallets such as MetaMask, Ethereum, and Exodus.

Rapid Evolution of AI-Integrated Malware

The discovery was made using the Cognitive Artifact Intelligence Research Network (CAIRN), a new open-source research toolkit released by Cisco Talos to hunt and classify AI-integrated malware. CAIRN identifies AI-related artefacts by analysing metadata, behaviour, and resource labels.

According to Fetterman, the transition from AI being an optional feature to a fully autonomous orchestrator has occurred within a single calendar year. While the autonomy provides attackers with unprecedented speed and scale, it also introduces new vulnerabilities. The malware’s reliance on commercial APIs means it is susceptible to provider refusals, malformed outputs, and infrastructure limitations.

Cisco Talos emphasized that there is currently no confirmed evidence of CLOSEDQUORUM being deployed in the wild.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.