New ClosedQuorum Windows malware uses AI for attack decisions
A newly discovered Windows malware called ClosedQuorum leverages Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously make decisions during attacks.

The cybersecurity landscape is facing a new evolution in threat tactics with the discovery of ClosedQuorum, a Windows malware that integrates artificial intelligence to drive its post-compromise activities.
According to BleepingComputer, this sophisticated malware relies on well-known AI models including Google Gemini, DeepSeek, Qwen, and Mistral to autonomously determine the best course of action after breaching a target system.
By delegating tactical decisions to AI, the malware can dynamically adapt to the environment of the compromised network instead of following rigid, pre-coded instructions, making it significantly harder to detect and mitigate.
This development serves as a stark reminder for cybersecurity professionals globally, highlighting how cybercriminals are weaponizing generative AI and large language models to automate complex attack chains.
As these smart threats emerge, organizations must evolve their defense strategies by moving beyond traditional detection methods and adopting advanced behavioral monitoring to counter AI-driven attacks effectively.



