Skip to main content

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

0
Medium
Published: 09/23/2026 (09/23/2026, 20:08:58 UTC)
Source: AlienVault OTX General

Description

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 20:36:14 UTC

Technical Analysis

CLOSEDQUORUM is a Windows infostealer malware that uniquely uses a consensus mechanism involving up to four AI models to decide its next actions, including credential theft and data exfiltration targeting Windows credentials, browser passwords, and crypto wallets. Despite this novel approach, Cisco Talos reports no evidence of the malware operating end-to-end successfully, and the public sample does not currently work.

Potential Impact

If fully operational, CLOSEDQUORUM could compromise sensitive user data such as Windows credentials, saved browser passwords, and cryptocurrency wallet information. However, there is no confirmed exploitation or successful deployment of this malware in the wild at this time.

Defensive Guidance

No official patch or remediation is available as this malware is not a software vulnerability but a threat actor tool. Since the public version does not function as intended and no active exploitation is reported, no immediate action is required beyond standard security best practices for credential protection and malware defense.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html"]
Pulse Id
6ab431db415b8cd13de69a7e

Indicators of Compromise

Hash

ValueDescriptionCopy
hash250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7
hash39ceeb8fd9a17098092434f43edaed18
MD5 of c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7
hashb8644f66e695101b1a3ff5a57be09c073db7922f
SHA1 of c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7
hash5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb
hashc13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f
hashc4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7
hasheddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5
hashf5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c
hash31a715d2d44448b55d9691fa0301b9f6
MD5 of 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb
hash6478400a4d00a8f755df453b47009212
MD5 of 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7
hash74e859da6c2d1c961af718b97873c564
MD5 of f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c
hash833cdd365d2dd29832a711dc2da5a584
MD5 of c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f
hasheb16b4f96693d5dca59711e8350bdad8
MD5 of eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5
hash12001dabf37f7d20a3bd8773cee9a5a89eb1bf54
SHA1 of 5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb
hash5e5ca8cda7f4640adc125225f4ec19c7ae75c89c
SHA1 of 250d4fa37488af9b025333fa17705573d721467b203765bc360890b4f5a90cd7
hash77b767fc5ff206df1eca760ffd3214e9df27135e
SHA1 of eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5
hashf495880eb6ee7bb930a9957f092f395695cf89a4
SHA1 of c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f
hashff15e9eaaf68b7a6be491e3e9342c8d3d05af960
SHA1 of f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c

Threat ID: 6ab433ebf7a7c54106464f12

Added to database: 09/23/2026, 20:17:47 UTC

Last enriched: 09/23/2026, 20:36:14 UTC

Last updated: 09/24/2026, 01:55:00 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses