This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
AI Analysis
Technical Summary
CLOSEDQUORUM is a Windows infostealer malware that uniquely uses a consensus mechanism involving up to four AI models to decide its next actions, including credential theft and data exfiltration targeting Windows credentials, browser passwords, and crypto wallets. Despite this novel approach, Cisco Talos reports no evidence of the malware operating end-to-end successfully, and the public sample does not currently work.
Potential Impact
If fully operational, CLOSEDQUORUM could compromise sensitive user data such as Windows credentials, saved browser passwords, and cryptocurrency wallet information. However, there is no confirmed exploitation or successful deployment of this malware in the wild at this time.
Mitigation Recommendations
No official patch or remediation is available as this malware is not a software vulnerability but a threat actor tool. Since the public version does not function as intended and no active exploitation is reported, no immediate action is required beyond standard security best practices for credential protection and malware defense.
Indicators of Compromise
- hash: 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7
- hash: 39ceeb8fd9a17098092434f43edaed18
- hash: b8644f66e695101b1a3ff5a57be09c073db7922f
- hash: 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb
- hash: c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f
- hash: c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7
- hash: eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5
- hash: f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c
- hash: 31a715d2d44448b55d9691fa0301b9f6
- hash: 6478400a4d00a8f755df453b47009212
- hash: 74e859da6c2d1c961af718b97873c564
- hash: 833cdd365d2dd29832a711dc2da5a584
- hash: eb16b4f96693d5dca59711e8350bdad8
- hash: 12001dabf37f7d20a3bd8773cee9a5a89eb1bf54
- hash: 5e5ca8cda7f4640adc125225f4ec19c7ae75c89c
- hash: 77b767fc5ff206df1eca760ffd3214e9df27135e
- hash: f495880eb6ee7bb930a9957f092f395695cf89a4
- hash: ff15e9eaaf68b7a6be491e3e9342c8d3d05af960
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
Description
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CLOSEDQUORUM is a Windows infostealer malware that uniquely uses a consensus mechanism involving up to four AI models to decide its next actions, including credential theft and data exfiltration targeting Windows credentials, browser passwords, and crypto wallets. Despite this novel approach, Cisco Talos reports no evidence of the malware operating end-to-end successfully, and the public sample does not currently work.
Potential Impact
If fully operational, CLOSEDQUORUM could compromise sensitive user data such as Windows credentials, saved browser passwords, and cryptocurrency wallet information. However, there is no confirmed exploitation or successful deployment of this malware in the wild at this time.
Defensive Guidance
No official patch or remediation is available as this malware is not a software vulnerability but a threat actor tool. Since the public version does not function as intended and no active exploitation is reported, no immediate action is required beyond standard security best practices for credential protection and malware defense.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html"]
- Pulse Id
- 6ab431db415b8cd13de69a7e
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7 | — | |
hash39ceeb8fd9a17098092434f43edaed18 | MD5 of c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7 | |
hashb8644f66e695101b1a3ff5a57be09c073db7922f | SHA1 of c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7 | |
hash5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb | — | |
hashc13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f | — | |
hashc4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7 | — | |
hasheddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5 | — | |
hashf5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c | — | |
hash31a715d2d44448b55d9691fa0301b9f6 | MD5 of 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb | |
hash6478400a4d00a8f755df453b47009212 | MD5 of 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7 | |
hash74e859da6c2d1c961af718b97873c564 | MD5 of f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c | |
hash833cdd365d2dd29832a711dc2da5a584 | MD5 of c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f | |
hasheb16b4f96693d5dca59711e8350bdad8 | MD5 of eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5 | |
hash12001dabf37f7d20a3bd8773cee9a5a89eb1bf54 | SHA1 of 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb | |
hash5e5ca8cda7f4640adc125225f4ec19c7ae75c89c | SHA1 of 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7 | |
hash77b767fc5ff206df1eca760ffd3214e9df27135e | SHA1 of eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5 | |
hashf495880eb6ee7bb930a9957f092f395695cf89a4 | SHA1 of c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f | |
hashff15e9eaaf68b7a6be491e3e9342c8d3d05af960 | SHA1 of f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c |
Threat ID: 6ab433ebf7a7c54106464f12
Added to database: 09/23/2026, 20:17:47 UTC
Last enriched: 09/23/2026, 20:36:14 UTC
Last updated: 09/24/2026, 01:55:00 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.