CLOSEDQUORUM malware delegates decisions about its actions to language models
Cisco Talos has described the CLOSEDQUORUM malware for Windows, which, instead of following an attacker's instructions, consults with up to four language models and acts based on their responses. Deployment in real-world attacks has not yet been confirmed.
Security analysts at Cisco Talos have described a malicious program called CLOSEDQUORUM designed for Windows, which, once launched, does not act according to the attacker's fixed instructions but instead delegates the decision about its next step to language models. According to the description, the program can query up to four different AIs and act based on their responses.
According to Cisco Talos, it has not yet been confirmed that CLOSEDQUORUM has actually been deployed in real-world attacks. This is therefore a description of a capability and a technique, not a documented campaign with specific victims.
For details, see the source article.
Why it matters
If the technique described by Cisco Talos spreads, it would mark a shift from malware with fixed logic to programs whose behavior is driven by the real-time responses of language models. This could make it harder for security teams to predict and apply signature-based detection of malicious code, since the same sample could behave differently depending on context. So far, this is a described capability without confirmed use in attacks, a distinction that is important to make from an active threat.
Relevant practical impact
What this means
For a business
Security teams should take into account that malware may use responses from language models to decide on further steps instead of relying on an attacker's fixed logic, which makes it harder to predict its behavior and can complicate traditional detection based on known patterns.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.