AI malware is becoming its own category: Researchers found a malicious program that uses multiple AI models to decide what to do
Researchers have reportedly found a malicious program that uses AI model to help decide what it should do next. The malware, called CLOSEDQUORUM , can contact up to four AI models, including DeepSeek , Qwen, Mistral and Google Gemini. Instead of relying only on instructions written by its developers, the program asks these AI systems for guidance and uses their responses to decide its next steps. Reported by Wired, the discovery was made by researchers at Cisco Talos , who have also created an open-source framework to track malware that uses AI.

How does the AI-powered malware workCLOSEDQUORUM is designed for Windows and can use several AI services at the same time. Researchers describe the setup as a kind of “hive mind”, because the malware can seek decisions from multiple AI models. If one AI service is unavailable, the others can continue working.
As stated in the report, researchers also found no mechanism that would allow a human to step in and control the process.
The malware is designed to steal login credentials and cryptocurrency. Researchers also found links to cybercrime forums discussing credit-card fraud dating back to 2025. However, they could not confirm who created CLOSEDQUORUM or whether it has been used in real-world attacks.
Researchers are finding more AI-powered malwareCisco Talos created the Cognitive Artifact Intelligence Research Network (CAIRN) after researchers began finding signs that attackers were integrating AI into malware. Ryan Fetterman of Cisco Talos said AI integration leaves behind identifiable “fingerprints” that can help researchers track and classify these programs.
“The core idea is that AI integration has these vestiges, like fingerprints, that are left behind... That gives us a signal that we can use to track these samples, classify them, and look at what's happening,” Fetterman said.
When Fetterman first searched for AI-integrated malware, he found only around nine named malware families, along with several proof-of-concept examples. After CAIRN was developed, researchers identified about 20 additional examples within a few months.
What the findings suggestThe findings suggest that AI is becoming more deeply integrated into some malware rather than simply being used by hackers to write code or create phishing messages. Matt Olney of Cisco Talos said attackers are now beginning to operationalise AI.
“Initially, everyone saw AI as a productivity tool, right?... Now what we're seeing is that it's becoming operationalized.”
He said AI could allow attackers to run more campaigns, target more systems and handle different computers because the technology can provide responses and guidance in the background.
How does the AI-powered malware workCLOSEDQUORUM is designed for Windows and can use several AI services at the same time. Researchers describe the setup as a kind of “hive mind”, because the malware can seek decisions from multiple AI models. If one AI service is unavailable, the others can continue working.
As stated in the report, researchers also found no mechanism that would allow a human to step in and control the process.
The malware is designed to steal login credentials and cryptocurrency. Researchers also found links to cybercrime forums discussing credit-card fraud dating back to 2025. However, they could not confirm who created CLOSEDQUORUM or whether it has been used in real-world attacks.
Researchers are finding more AI-powered malwareCisco Talos created the Cognitive Artifact Intelligence Research Network (CAIRN) after researchers began finding signs that attackers were integrating AI into malware. Ryan Fetterman of Cisco Talos said AI integration leaves behind identifiable “fingerprints” that can help researchers track and classify these programs.
“The core idea is that AI integration has these vestiges, like fingerprints, that are left behind... That gives us a signal that we can use to track these samples, classify them, and look at what's happening,” Fetterman said.
When Fetterman first searched for AI-integrated malware, he found only around nine named malware families, along with several proof-of-concept examples. After CAIRN was developed, researchers identified about 20 additional examples within a few months.
What the findings suggestThe findings suggest that AI is becoming more deeply integrated into some malware rather than simply being used by hackers to write code or create phishing messages. Matt Olney of Cisco Talos said attackers are now beginning to operationalise AI.
“Initially, everyone saw AI as a productivity tool, right?... Now what we're seeing is that it's becoming operationalized.”
He said AI could allow attackers to run more campaigns, target more systems and handle different computers because the technology can provide responses and guidance in the background.
Next Story