AI‑Powered Malware Lets Four Bots Vote on Data Theft, Researchers Reveal
Cisco Talos researchers have identified a novel piece of malware, dubbed CLOSEDQUORUM, that autonomously decides its next action by consulting four separate commercial artificial‑intelligence models. The code does not rely on a human operator; instead, it aggregates the models' recommendations and proceeds based on the majority vote.
The discovered malware first infiltrates a target system, then extracts a snapshot of available files and system information. It forwards this data to the four AI services, each of which evaluates the snapshot and suggests a course of action—such as exfiltrating credentials, encrypting files, or installing additional payloads. CLOSEDQUORUM tallies the suggestions and executes the option that receives the most votes.
Security analysts note that this approach represents a shift from traditional command‑and‑control architectures, where a remote server dictates behavior. By leveraging publicly accessible AI models, the attackers can obscure their infrastructure and reduce the need for a persistent control channel, making detection and attribution more difficult.
The technique also raises concerns about the misuse of widely available AI tools. Commercial providers typically impose usage policies, but the malware appears to frame its queries as innocuous data‑analysis requests, sidestepping safeguards. Researchers stress that the models themselves are not compromised; they are merely being co‑opted to provide rapid decision‑making for malicious code.
Experts suggest that defenders may need to monitor outbound traffic for patterns indicative of AI‑service calls, especially from processes that do not normally interact with cloud APIs. Additionally, organizations could implement stricter egress filtering and employ anomaly‑based detection to flag unexpected data flows to AI endpoints.
While the full scope of campaigns using CLOSEDQUORUM remains under investigation, its emergence underscores the expanding toolbox available to cybercriminals. As AI becomes more integrated into both defensive and offensive operations, the security community faces the challenge of balancing the benefits of these technologies against the risk of them being weaponized in novel ways.
Comments (0)
Be the first to comment.
Join the discussion