A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’ credentials and cryptocurrency wallets.
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
About this summary. This is a short, independently written summary of an article first published by The Register. Cyber Security News did not report or verify the underlying story. Read the original: https://www.theregister.com/security/2026/09/22/windows-closedquorum-malware-uses-ai-models-to-autonomously-select-post-compromise-actions/5298435

Source attribution: headline and facts are from The Register (theregister.com). Summary method: excerpt of the source description. See our source attribution policy.

