AI Malware Has Entered a New Phase: This Virus Can Ask Multiple AI Models What to Do Next
Most AI malware stories are about attackers using AI to write malicious code faster. Cisco Talos has now documented something different: a Windows implant called CLOSEDQUORUM that can ask multiple AI models to decide its next action. Here is what the researchers actually found, why it matters, and why AI malware may be changing from human-assisted to machine-directed attacks.

AI Malware Has Entered a New Phase
For the last few years, the most common story around AI and cybercrime has been fairly simple: attackers use AI to write code, create phishing messages, research targets or automate parts of an attack.
That still happens. But researchers are now seeing something more unusual.
Cisco Talos has documented a Windows malware sample called CLOSEDQUORUM that uses multiple large language models to help decide what the malware should do next. Instead of treating AI as a tool used by the person behind the attack, CLOSEDQUORUM moves part of the decision making process inside the malware itself.
That distinction is important because it changes the question from whether criminals can use AI to build malware faster to whether malware itself can start making operational decisions.
Cisco Talos does not have confirmation that CLOSEDQUORUM was deployed in the wild. The sample they analyzed appears to be a real malware project, but the publicly distributed build contained placeholder credentials and could not complete its full AI-driven operation as distributed. That limitation is important when interpreting the discovery.
What Cisco Talos Actually Found
The discovery came from a new Cisco Talos research project called CAIRN, short for Cognitive Artifact Intelligence Research Network.
CAIRN is designed to find malware that interacts with AI systems. Instead of requiring researchers to download and execute every suspicious binary, the toolkit searches metadata for what Talos calls cognitive artifacts.
These artifacts can include AI provider addresses, embedded prompts, tool-calling structures, API key patterns, AI-related strings and text designed to interfere with AI-based malware analysis.
Talos released CAIRN as an open-source research toolkit in September 2026 and used it to investigate a growing collection of AI-integrated malware.
The first major finding published from that research was CLOSEDQUORUM.
What Makes CLOSEDQUORUM Different?
Traditional malware normally receives instructions from an attacker-controlled command and control server. The attacker decides what the malware should do and sends the instruction to the infected machine.
CLOSEDQUORUM changes that model.
According to Talos, the malware can send information about its target to a group of large language models and use their responses to select its next action.
The architecture can involve four different AI providers: DeepSeek, Qwen, Mistral and Google Gemini.
The models are not simply being asked to generate a paragraph or write a piece of code. Their responses are constrained into a decision format that the malware can process.
The malware then uses the result to select from predefined actions.
That makes the AI component function more like a decision layer inside the malware.
Why Are Four AI Models Being Used?
The name CLOSEDQUORUM comes from the way the system makes decisions.
A quorum is a group large enough to make a decision. In the CLOSEDQUORUM design described by Talos, multiple AI models can independently provide a decision and the malware selects the option receiving the most votes.
That is an unusual design for malware.
Instead of depending entirely on one model, the developer created a form of AI consensus mechanism. The idea appears to be that several models can independently evaluate the same situation and collectively determine the next action.
The models therefore become part of the malware's command and control architecture.
The AI Does Not Have Unlimited Freedom
This is where the story becomes more interesting than the headline suggests.
CLOSEDQUORUM is not an AI that can invent any attack it wants from scratch.
Talos found that the model responses are constrained by a predefined decision schema. The AI chooses between actions that the malware already knows how to perform.
That means the system is closer to AI-directed orchestration than completely unrestricted autonomous hacking.
The distinction matters because it shows one practical way attackers could use language models inside malware without giving a model unrestricted control over the computer.
The malware defines the available actions. The AI chooses between them.
What Can the Malware Actually Do?
Talos found functionality associated with credential and cryptocurrency wallet theft, process injection and other offensive capabilities.
One decision can trigger several credential theft functions, while another can route execution toward different process injection techniques.
These capabilities themselves are not completely new. Malware has been stealing credentials and injecting code into processes for years.
The unusual part is how the researchers found those capabilities being connected to an AI-driven decision loop.
This is why calling CLOSEDQUORUM simply an AI virus misses the important part of the discovery.
The innovation is not that the malware suddenly learned how to steal credentials. It is that an AI system was placed in the decision path between the malware and the action it takes.
The Most Important Detail: It May Not Have Been Used in the Wild
This is the part many headlines can easily get wrong.
Cisco Talos explicitly says it does not have confirmation of in-the-wild deployment of CLOSEDQUORUM.
The publicly observed distribution build also contained placeholder API credentials and a dummy webhook, meaning researchers could not observe the complete end-to-end AI operation from that public build alone.
Talos used static analysis and development builds to reconstruct how the system was designed to operate.
That means CLOSEDQUORUM should currently be understood as a documented malware design and capability, not proof that criminals are already running large autonomous AI malware campaigns everywhere.
That distinction makes the discovery more credible, not less interesting.
Security researchers can see the architecture being developed before it necessarily becomes a widespread operational threat.
So Why Is This Still a Big Deal?
The answer is what Talos calls effort displacement.
AI has already made some cybercrime tasks faster. An attacker can use an AI model to write code, generate variations, summarize technical information or automate repetitive work.
But the human operator is still involved.
They decide what to target, what action to take and when to take it.
A system like CLOSEDQUORUM attempts to move some of those decisions into the malware itself.
That means the attacker does not necessarily need to remain involved in every step of an operation.
The malware can continue making decisions according to its programmed rules and the information available to the AI models.
This is a subtle change, but it could become important as AI agents become better at reasoning through changing environments.
AI Malware Is Not Automatically More Dangerous
There is another side to the story that is easy to miss.
Palo Alto Networks' Unit 42 analyzed 405 samples associated with AI-enabled malware and found that most were not evidence of widespread production attacks. Its research found that approximately 97 percent of the samples existed in research repositories, sandboxes or security validation environments rather than appearing in customer endpoint telemetry.
Only 12 samples from the dataset appeared on protected production endpoints during the observation period.
Unit 42 also reported that the AI-enabled samples reaching its customer environments were detected using conventional security mechanisms such as behavioral analytics, sandboxing, code-signing anomaly detection and endpoint protection.
So the current evidence does not support the idea that AI malware has suddenly made existing cybersecurity defenses obsolete.
The more accurate picture is that AI is becoming another component that malware developers can integrate into existing attack techniques.
The Interesting Part Is the Direction of Travel
Taken together, the research from Cisco Talos and Unit 42 paints a more complicated picture than either extreme.
On one side, there is a rapidly growing amount of experimentation with AI-integrated malware. On the other, most of the samples researchers encounter are still experimental, research-oriented or unsuccessful at reaching protected production environments.
But within that experimental ecosystem, the architecture itself is changing.
AI has moved from helping write malware to being incorporated into malware workflows. CAIRN's findings show several different ways AI can appear inside malicious software, including AI-assisted offensive tools, AI credential theft, malicious AI packages and agentic abuse tools.
CLOSEDQUORUM represents the more autonomous end of that spectrum.
Why CAIRN Could Be More Important Than One Malware Sample
The CLOSEDQUORUM discovery is only the first result from CAIRN.
That may ultimately be more significant than the malware itself.
Traditional malware hunting often depends on finding known hashes, domains, strings or other indicators. But AI-integrated malware can change quickly, and the AI portion of a malicious tool may leave different traces from one project to another.
CAIRN takes a different approach by looking for the artifacts created when malware interacts with AI systems.
The toolkit can search for provider endpoints, prompts, tool-calling structures, AI-analysis evasion strings and other clues. It can then connect related samples through metadata relationships and semantic similarity.
That gives researchers a way to study the development of AI-integrated malware as a category rather than treating every new sample as an isolated incident.
What This Means for Businesses
For most businesses, the immediate lesson is not to start blocking every connection to an AI provider.
That would create obvious problems because legitimate applications increasingly communicate with AI services.
The more useful approach is behavioral.
A normal business application contacting an AI service is not automatically suspicious. A previously unknown Windows executable that contacts several AI providers while also accessing credential stores, performing process injection and communicating through an unusual webhook is a very different pattern.
This is one reason AI-related security monitoring will increasingly need to understand context rather than relying on simple domain blocklists.
Businesses should also pay attention to the AI credentials used by their own applications. API keys, model access tokens and AI service credentials are becoming valuable targets because attackers can potentially use them to access expensive infrastructure or build their own AI-powered tooling.
The New Security Question
For years, security teams asked whether malware could execute a particular action.
With AI-integrated malware, another question is becoming important: who or what decides when that action happens?
If the answer is a human operator, the attack still has a human decision point.
If the answer is an automated rule, the behavior is predictable within the limits of that rule.
If the answer is an AI model evaluating the environment and selecting from several actions, the security team has a new layer to understand.
That does not automatically make the attack unstoppable. But it changes the architecture defenders need to analyze.
The Bottom Line
CLOSEDQUORUM is not proof that autonomous AI malware has already become a widespread real-world threat.
It is something more specific and, in some ways, more useful: a publicly documented example of malware architecture in which multiple AI models can participate in tactical decision making.
The current evidence suggests that most AI-enabled malware remains experimental or limited in real-world deployment. Existing security technologies are still detecting many of these threats.
But the direction is worth watching.
The first generation of AI malware mostly used AI as an assistant for the attacker. CLOSEDQUORUM demonstrates a different idea: letting AI become part of the malware's decision loop.
If that architecture becomes reliable, the next evolution of AI-assisted cybercrime may not be about attackers writing malware faster. It may be about malware requiring less attention from its operator.
That is the part of the AI security story that businesses should be watching now.
FAQ
What is CLOSEDQUORUM malware?
CLOSEDQUORUM is a Windows malware implant documented by Cisco Talos that uses multiple large language models to help select its next tactical action.
Is CLOSEDQUORUM actively attacking people?
Cisco Talos has not confirmed in-the-wild deployment of CLOSEDQUORUM. The researchers reconstructed its autonomous AI decision architecture from the malware and development artifacts.
Which AI models does CLOSEDQUORUM use?
Cisco Talos identified integrations for DeepSeek, Qwen, Mistral and Google Gemini. The architecture can use multiple models to vote on the next action.
Can AI malware make decisions without a human?
Some AI-integrated malware is being designed to reduce the need for continuous human instructions. CLOSEDQUORUM is a documented example where AI models can participate in selecting the malware's next action.
Is AI malware already widespread?
Current research does not support that conclusion. Unit 42 analyzed 405 AI-associated malware samples and found that approximately 97 percent were present only in research, sandbox or security-validation environments during its study.
What is CAIRN?
CAIRN is Cisco Talos' open-source research toolkit for identifying, classifying and tracking AI-integrated malware through artifacts such as AI provider endpoints, prompts, orchestration logic and other metadata.
Does AI malware require completely new cybersecurity defenses?
Not necessarily. Unit 42 reported that the AI-enabled malware samples it observed in production were detected by existing security mechanisms including behavioral analytics, sandboxing and endpoint protection. However, defenders increasingly need to understand AI-specific artifacts and the context in which AI services are being accessed.
What is the biggest change AI could bring to malware?
One potential change is effort displacement: moving parts of the attack decision process from a human operator into software. CLOSEDQUORUM provides an early documented example of that architecture, although its real-world deployment remains unconfirmed.