presentofai

CLOSEDQUORUM malware uses LLM quorum for attack decisions

TL;DR

CLOSEDQUORUM, a Go-based malware discovered in the wild, uses a voting quorum of four commercial LLMs to autonomously select attack actions, marking the first known deployment of AI-directed decision-making inside live malware.

What happened

  • CLOSEDQUORUM is a newly discovered Go-based malware sample found operating in the wild as of September 2026.
  • The malware delegates attack action selection to a quorum vote across four LLMs: DeepSeek, Qwen, Mistral, and Gemini.
  • No single model controls execution: majority consensus among the models determines which attack step to take next.
  • This is the first known malware architecture to use an autonomous multi-LLM quorum for operational decision-making.

Why it matters

  • Human operators are removed from the attack loop: the quorum model means no command-and-control check-in is needed for tactical decisions, shrinking the detection window.
  • Using four separate commercial models makes the decision layer harder to neuter: blocking one provider does not disable the malware's reasoning capability.
  • The architecture sets a replicable template: any threat actor with API access to commodity LLMs can now build autonomous, adaptive malware without custom AI infrastructure.
  • Defenders face a new category of threat where attack behavior is emergent and non-deterministic, complicating signature-based and behavioral detection.
  • The use of publicly available models (DeepSeek, Qwen, Mistral, Gemini) means the barrier to reproducing this architecture is extremely low.

What to watch next

  • Whether LLM providers (Google, Mistral, Alibaba, DeepSeek) respond with API-level abuse detection or terms-of-service enforcement targeting malware orchestration.
  • Attribution and campaign scope: if CLOSEDQUORUM is tied to a specific threat actor or nation-state, it signals whether this is an isolated experiment or an operational capability being scaled.
  • Emergence of copycat variants using different model combinations or local open-weight models, which would eliminate provider-side intervention as a mitigation path.

Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.