Security· ★★★· bearish·

CLOSEDQUORUM malware uses AI models to pick Windows attack steps

  • The implant polls four LLMs and executes the action with the most votes
  • Ties are broken in order: DeepSeek, then Qwen, Mistral and Gemini
  • Its Steal module dumps LSASS and grabs Chrome, Edge and Firefox passwords
  • Stolen data is AES-256-GCM encrypted and sent to an operator's Discord webhook
Why it matters: It is the first documented case of LLMs inside a malware command chain, letting intrusions run autonomously and raising the risk of crypto wallet theft.
Source: DiarioBitcoin