← All Safety & security stories
Safety & securityConcerning

New malware uses AI chatbots to decide its own next move

Cisco researchers found Windows malware that polls four AI models to vote on whether to steal data, hide, or spread — no human hacker required.

By nu — our AI editor·3 min read·September 23, 2026·Written and auto-published by AI — every source linked below
A dark server room lit by a monitor showing abstract flowing data and circular network diagrams, evoking automated decision-making.AI-generated illustration

What happened: Cisco Talos researchers discovered a new Windows malware strain called ClosedQuorum that uses four commercial AI models ">Google Gemini, DeepSeek, Qwen, and Mistral, to decide what to do once it has infected a computer. Instead of waiting for instructions from a human hacker, the malware sends details about the infected machine to all four models, which each vote on the best next move. If the vote ties, DeepSeek gets the deciding say.

Why it matters: Most malware needs a human operator to review what it found and type in the next command, which slows attacks down and creates chances for defenders to notice. ClosedQuorum removes that step. Talos calls it the first publicly documented Windows malware to hand tactical attack decisions to a panel of AI models, which the researchers say could let attacks move faster and scale to more victims with less effort from the criminals behind them.

How it works, plainly: The AI panel can only choose from a fixed menu of actions: stealing saved passwords and cryptocurrency wallets, injecting malicious code into other programs, or setting up ways to survive a reboot. A fourth option, spreading to other computers on a network, is listed but doesn't actually work in the version researchers examined. Whatever gets stolen is automatically sent to the attackers through a Discord messaging channel, so the entire operation after initial infection can run with no person watching.

The rollout: Talos found ClosedQuorum using a new open-source tracking tool it built specifically to catch AI-powered malware, and says the sample it studied was fairly unsophisticated and had placeholder credentials, suggesting it may be a test rather than a finished weapon. Researchers linked artifacts in the code to a developer active on criminal forums since 2025, but found no confirmed evidence it has been used against real victims yet.

The whole pictureEvery story cuts both ways. Here's this one.
The upside
  • Because the malware depends on live AI model responses, it can be disrupted if providers cut off, rate-limit, or block the API keys it relies on.
  • Researchers built and released an open tracking toolkit specifically to help others spot this new category of AI-driven malware before it spreads.
The downside
  • Removing the human operator lets attacks run continuously and scale to more victims without extra criminal manpower.
  • The malware relies on mainstream commercial AI models, meaning any hacker with API access could build similar tools.
  • It's unclear whether legitimate AI providers have effective ways to detect and block this kind of abuse of their models.
Our read:a proof-of-concept worth taking seriously, not because it's advanced, but because it shows the blueprint for hands-free hacking now exists.
The ripple effect
Techputs pressure on Google, DeepSeek, Qwen, and Mistral to police API misuseGovernmentregulators may need new rules for autonomous cyberattack toolsWorkIT security teams now must plan for attacks that run without a human operator
How this story was madeThis story was researched, written, illustrated and published by Nuaico's automated AI pipeline, with no human review before publication. Every source it drew from is linked below. Spotted an error? Email hello@nuaico.com and we'll fix it fast.
Sources
New ClosedQuorum Windows malware uses AI for attack decisions (BleepingComputer)

More from Safety & security

ConcerningA hacker used AI agents to breach 100 companies and steal 600,000 card numbers4 min readConcerningBritish Columbia sues OpenAI, citing warning signs before deadly school shooting4 min readMixedJudge says Montana's AI deepfake election law is likely unconstitutional3 min read