Researchers discover "AI autonomous malware": calling four major chatbots at the same time to decide attack actions autonomously

📅 2026-09-23

Abstract:

Cybersecurity researchers recently discovered an unusual new type of Windows malware. Different from past attack tools that used artificial intelligence to assist in writing codes or creating phishing content, this malware called CLOSEDQUORUM directly incorporates multiple large-scale language models into its own control system and can independently decide the next step during operation. It is considered to represent a new stage in the development of AI malware.

The discovery comes from Cisco Talos, a security team under Cisco. Researchers said that CLOSEDQUORUM will simultaneously interact with four large language models: DeepSeek, Qwen, Mistral, and Google Gemini. Before performing tasks on the infected device, it will first send requests to these models and collect feedback, and then decide subsequent actions based on the results.

This design gives the malware a degree of redundancy. Even if one of the AI ​​services is inaccessible, the program can still continue to make requests to other models and keep running, making it more resilient than traditional malware that relies on a single control server.

What is even more concerning is that the researchers did not find manual remote control entrances in the traditional sense in the sample. In other words, once the program starts running, it does not need to continue to receive specific instructions from the hacker, but independently plans subsequent operations through feedback from multiple large-scale language models.

According to the analysis results, CLOSEDQUORUM’s main goal is to steal user account passwords and cryptocurrency assets. The research team also found that the malware was related to credit card fraud network activities dating back to 2025. However, so far, researchers have not been able to confirm the identity of the specific developer, nor can they determine whether the tool has been used in real attacks.

This discovery stems from a new research initiative by Cisco Talos. In response to the trend of more and more artificial intelligence being incorporated into attack tools, researchers developed an open source framework called CAIRN (Cognitive Artifact Intelligence Research Network) to identify and track malware that relies on AI services to run.

The research team believes that the combination of artificial intelligence and malware will leave special technical traces, just like a digital fingerprint. These traces can help security analysts identify samples, establish classification systems, and track how attackers integrate large language models into attack tools.

CAIRN analyzes metadata in malware and technical characteristics related to AI services, and generates a unique identifier for the sample. The system then categorizes malware with similar characteristics, helping researchers identify new attack patterns and potential trends.

Security experts point out that most AI-related malware that emerged in the past year still mainly uses large models as auxiliary tools. For example, help generate code, write phishing emails, automate attack processes, or provide remote decision support. The biggest difference between CLOSEDQUORUM and these cases is that it directly integrates the large language model into the command and control mechanism itself.

Previously, the Ukrainian cybersecurity agency had disclosed a malware called LAMEHUG, which accessed the Tongyi Qianwen model through the Hugging Face platform to obtain execution commands. However, researchers say that cases like CLOSEDQUORUM that call multiple models at the same time and drive the attack process in a "collective decision-making" manner are still very rare.

Although the number of currently known AI malware is still limited, the security community generally believes that the development direction of such tools deserves great attention. In the past, large models played more of a role in improving hacker productivity; now, researchers have begun to see a gradual shift in artificial intelligence from "auxiliary tools" to attacking the infrastructure itself.

Industry insiders believe that as the capabilities of large-scale language models continue to improve, future malware may have stronger autonomous decision-making capabilities, more complex environmental adaptability, and more flexible attack path selection capabilities. Although this discovery is still in its early stages, it has given security researchers an early glimpse into what the next generation of intelligent cyberattacks may look like.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet