Security · September 27, 2026
AI Driven Malware Chooses Its Own Path Without Human Command
A newly discovered malicious program named CLOSEDQUORUM operates without needing human instructions after initial access. It selects subsequent actions by querying four distinct AI models, each providing recommendations tailored to the current environment. The program evaluates these suggestions through a voting mechanism, adopting the option with the highest score; ties are resolved by favoring DeepSeek.
Once a decision is executed, the process restarts, allowing the malware to adapt its behavior based on new inputs. This dynamic decision loop enables CLOSEDQUORUM to modify its attack trajectory in real time, targeting stored passwords and cryptocurrency wallets such as MetaMask, as well as browser credentials from Chrome, Edge, and Firefox. The malware continuously searches for valuable data, including saved passwords and digital wallet contents, while avoiding the need for the attacker to remain continuously present.
Researchers identified CLOSEDQUORUM within the CAIRN project, which examines AI supported malicious software, and released detection guidance for security systems. No active campaigns have been observed, and the operators remain unidentified.