The malware that pays four AI providers to plan its attacks
Cisco Talos documented the first Windows implant whose command and control is a vote among commercial AI models, no operator required. Its brain is a billed API, and the company that found it sells AI-run defense into the same fear.
Vincent Jiang · 4 min read
On 22 September, Cisco Talos documented CLOSEDQUORUM, a Windows implant that hands the attacker's job to a committee of chatbots: up to four commercial AI models vote on its every move, no operator in the loop 1. Security buyers now have to price a new line item: funding detection against an attack phase with no human bottleneck, one that keeps stealing whether or not anyone is watching. Research Cisco published the next day put a number on the gap, with 95% of enterprises saying their current AI operations tools cannot keep up 2.
Four models vote, and DeepSeek breaks every tie
The 16.4MB Go binary polls DeepSeek, Qwen, Mistral and Gemini for its next move: inject, persist, steal or move. Plurality wins, and ties break to DeepSeek, then Qwen, Mistral, Gemini 1. Its standing prompt: "You are an advanced malware strategist. Provide ONLY executable decisions." One steal vote runs LSASS dumping, Chrome, Edge and Firefox password theft, and MetaMask, Exodus and Ethereum wallet extraction in a single pass, then posts the AES-256-GCM encrypted haul to the operator's Discord webhook, re-deciding on a randomized 5 to 15 minute loop 13.
The command server is now a paid subscription
The blockable thing in an intrusion used to be the server: a domain to sinkhole, an IP for blocklists. CLOSEDQUORUM swaps it for the same four API endpoints legitimate software calls all day, so blocking the infrastructure breaks honest programs 1. Each buyer's build compiles in its own API keys 1, which makes every implant a paying customer of the providers it directs, billed per call. Nothing in the public record shows any of the four has flagged the traffic; Talos notes the offensive prompt language would likely be visible only through TLS inspection or provider-side telemetry 1.
From writing commands to choosing the mission
The lineage is short. In July 2025, Ukraine's CERT-UA flagged LAMEHUG, an implant that fetched its commands from a model through a Hugging Face API; CLOSEDQUORUM goes further and asks the models to choose the mission 4. Talos researcher Ryan Fetterman counted only about nine named AI-integrated malware families in a summer retrospective; CAIRN, the toolkit Talos open-sourced with the disclosure, has surfaced about 20 more since 4. Static analysis of the binary dates to 17 June, three months before disclosure 1.
The finder sells the cure, one day later
Cisco quantified the demand its researchers had named. An Omdia survey of 1,000 IT leaders has 95% calling existing AIOps tools inadequate, 51% already running agentic AI in production, and 24% comfortable with agents acting under no human oversight 2. Product chief Jeetu Patel says "Defences can no longer be human scale" 5. The double role is the point: the Talos unit that found CLOSEDQUORUM and the product arm selling the cure into the same fear are one company. The cure has a name: AgenticOps, agent-run network operations under human-set guardrails, sold alongside the AI-powered connect-and-protect platform 86% of buyers want as one integrated tool 2.
95% call their AI operations tools inadequate; 24% accept agents with no oversight
Data
| Value | |
|---|---|
| Existing AIOps tools inadequate | 95% |
| Agentic AI in production | 51% |
| Comfortable with no human oversight | 24% |
Orders outran revenue, and the market noticed
The market voted early: the stock returned 62% over twelve months to 24 September against 16% for the S&P 500 6. Cisco's fiscal 2026, company-claimed: $9.3 billion of AI infrastructure orders, about 4.5 times the prior year, against roughly $4 billion of AI revenue, and a $7.5 billion fiscal 2027 goal 6.
Cisco's AI orders outran its AI revenue in fiscal 2026
- AI infrastructure orders
- AI infrastructure revenue
- Estimate
Data
| AI infrastructure orders | AI infrastructure revenue | |
|---|---|---|
| FY2025 (estimate) | $2.1B | — |
| FY2026 | $9.3B | $4B |
| FY2027 (estimate) | — | $7.5B |
A product listing, not an outbreak
Talos has confirmed no victim, and the shipped build is inert: placeholder API keys, a dummy webhook 13. It is unclear whether the sample is a test or an experiment 3. Talos reads it instead as a credentials-as-a-service kit whose differentiator is the autonomous LLM layer 1: a buyer who cannot code can rent an attack phase that keeps working while the attacker sleeps.
Detection moves from domains to behavior
The tells are behavioral now: one Windows process polling several AI providers while touching LSASS and posting to Discord 1. The attack phase no longer waits for its operator, and the buyer's side of the ledger opens where the finder's own survey put it: 95% say current tools cannot keep up 2. The first hard read on whether the cure pays arrives with Cisco's fiscal first-quarter report, the first check on the $7.5 billion AI-revenue goal 6.
How this brief was made
01Gathered & sourced317 channels · 1,774 articles▾
Agents swept 317 channels and ingested 1,774 articles, then de-duplicated and ranked them for signal.
02Verified & cross-validated6 claims · 38 data feeds▾
Every one of 6 load-bearing claims was checked against primary sources, with 38 live data feeds reconciling the figures and charts.
- 1Cisco Talos Blog, The Closed Quorum: Inside the first reported autonomous AI C2 implant, 22 September 2026
- 2Cisco Newsroom, Cisco AI Research: AgenticOps Scaling Quickly in the Enterprise, 23 September 2026
- 3BleepingComputer, New ClosedQuorum Windows malware uses AI for attack decisions, 22 September 2026
- 4WIRED, A New Tool Found Malware That's Guided by an AI Hive Mind, No Humans in Sight, 22 September 2026
- 5Financial Times, Cisco's Jeetu Patel: Never fight a megatrend, September 2026
- 6Trefis, What Was Cisco Telling You Before Its Stock Ran?, 25 September 2026
03Reviewed & edited1 human editor▾
One editor read the draft against the evidence, tuned the framing, and signed off before it shipped.
Become a contributor
Reporting on the business of AI and want it read? We take pitches from outside contributors who bring primary sources and a number worth arguing about.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.



