---
title: "Malware holds a board meeting, and attendance by humans is not required"
description: "Cisco Talos says CLOSEDQUORUM lets four chatbots vote on whether to steal your passwords"
author: "Tomasz Idle"
published: 2026-09-22T21:33:29Z
modified: 2026-09-27T06:21:16Z
url: https://rews.cc/a/malware-holds-a-board-meeting-and-attendance-by-humans-is-no-6f874c
language: en
tags: ["malware", "ai", "cybersecurity", "openai", "deepseek", "tech"]
publisher: "Rews (https://rews.cc)"
---

# Malware holds a board meeting, and attendance by humans is not required

*Cisco Talos says CLOSEDQUORUM lets four chatbots vote on whether to steal your passwords*

By Tomasz Idle · September 22, 2026 · https://rews.cc/a/malware-holds-a-board-meeting-and-attendance-by-humans-is-no-6f874c

## In brief

- Cisco Talos says CLOSEDQUORUM is the first publicly documented Windows implant using LLMs for command-and-control
- The malware queries up to four models — Gemini, DeepSeek, Qwen and Mistral — which vote on predefined post-compromise actions
- Actions include stealing LSASS and browser credentials plus MetaMask, Exodus and Ethereum wallets; loot goes to Discord
- Talos has not seen in-the-wild deployment; forum artifacts link the developer to 2025 carding posts
- Talos open-sourced its CAIRN toolkit for hunting AI-integrated malware and recommends behavioural detection over domain blocking

Every organisation eventually confronts the question of middle management: the layer of people whose job is to look at a situation and decide which of three obvious things to do about it. Industry’s answer, for a while now, has been to lay them off and buy a software subscription. It was only a matter of time before the people who write Windows malware reached the same conclusion.

That, in essence, is the finding Cisco Talos published on Tuesday, according to The Register: a new Windows implant it calls CLOSEDQUORUM, which takes the one interesting decision in a computer break-in — what to steal first — and delegates it to a committee of large language models. Talos describes it as, to its knowledge, the first publicly documented Windows implant to use LLMs for command-and-control. The humans, having built the thing, are no longer invited to the meetings.

The committee is oddly specific. Once deployed on a victim machine, the Go-based malware can query up to four LLM providers — Google Gemini, DeepSeek, Qwen and Mistral — asking each in turn to vote on the next move from a menu of predefined actions. The verdicts are tallied and the binary acts on them. If the vote is tied, there is a chain of command: DeepSeek’s vote takes precedence, then Qwen’s, then Mistral’s, then Gemini’s. Somewhere in a criminal enterprise, a person sat down and thought carefully about tie-breaking procedure, which is more governance forethought than many actual corporations manage.

> The session is closed; no humans are admitted

That line comes from Talos analyst Ryan Fetterman, writing on Tuesday, who added: “Four models are queried in sequence, their independent verdicts tallied, and the binary acts, based on their judgment.” He calls the technique “effort displacement” — moving a phase of the attack from a human operator to AI systems. “Human operators are bound by attention, working hours, and cognitive load,” he wrote. “It does not go offline when the attacker sleeps.” The malware, in other words, has achieved what every employer claims to want: a decision-maker that never takes a lunch break and has no opinions about the thermostat.

## The agenda items

Before anyone pictures a chatbot inventing diabolical new crimes in real time, the menu is fixed, and short. The models must choose from what Talos found as “ONLY executable decisions” — a constraint spelled out in the system prompt extracted from the binary, which also informs each model: “You are an advanced malware strategist.” The pretension of that title deserves a moment of silence. The strategist’s three options:

Steal, which simultaneously dumps LSASS memory for Windows credentials, lifts saved browser passwords from Chrome, Edge and Firefox, and extracts cryptocurrency wallet data including MetaMask, Exodus and Ethereum. Inject, which generates shellcode and runs it through process hollowing or Early Bird injection. And Persist, which digs the malware in so it survives on the infected device. So: rob the place, plant something, or change the locks. The grand strategy of the machine age turns out to be a multiple-choice quiz with three answers.

The plumbing is equally mundane, which is rather the point. Talos believes the developer hands each operator a customised executable with that operator’s Discord webhook and LLM API keys baked in at compile time — yes, the loot pipeline runs through Discord, the chat app. Stolen credentials arrive in the operator’s channel encrypted with AES-256-GCM, under a daily rotating key the operator derives from the message timestamp. Enterprise-grade key management, consumer-grade everything else.

## Found before it was used

Here the story takes a slightly unusual turn for malware news: nobody, as far as Talos can tell, has actually been robbed by this thing yet. The threat hunters have not observed CLOSEDQUORUM deployed in the wild. They found the binary using CAIRN — the Cognitive Artifact Intelligence Research Network, a toolkit Talos built for hunting, classifying and tracking AI-integrated malware, and which it also released as an open source repository on Tuesday. Artifacts in the binary tie its developer to postings on carding-related criminal forums dating back to 2025. So this is less a report of a crime wave than a photograph of someone’s business plan, discovered early, still warm.

That is worth sitting with. The malware economy has reached the productisation stage for its experimental AI features — a developer builds the wrapper, operators buy customised builds, the chatbots provide the judgement, and the stolen passwords arrive by push notification. The innovation is not artificial intelligence. It is the franchise model.

For defenders, Fetterman’s advice is to stop trying to block the destinations and start watching the behaviour. Domain blocking is a losing game here, he argues, because every endpoint on the list is legitimate on its own. “Legitimate applications may contact DeepSeek, OpenRouter, Mistral, Gemini, or Discord independently,” he wrote. “Far fewer should contact several of them while also accessing LSASS, injecting into suspended processes, or creating WMI persistence.” The tell is not where the program phones; it is that it phones four oracles and then starts rifling the drawers.

There is a temptation, with any story about AI, to reach for the word autonomy and shudder. Resist it. What Talos found is a burglar who has outsourced the moment of hesitation at the window — not to a smarter criminal, but to a quorum of four language models performing their unanimous impression of decisiveness, with a tie-breaking rule for when the impression falters. The crimes are the same crimes. The passwords are the same passwords. Only the org chart has changed, flattened by exactly one layer: the layer that used to be awake.

It turns out the machines did not come for the workers first. They came for the foreman.
