
CLOSEDQUORUM malware uses AI models to pick Windows attack steps
- —The implant polls four LLMs and executes the action with the most votes
- —Ties are broken in order: DeepSeek, then Qwen, Mistral and Gemini
- —Its Steal module dumps LSASS and grabs Chrome, Edge and Firefox passwords
- —Stolen data is AES-256-GCM encrypted and sent to an operator's Discord webhook
Why it matters: It is the first documented case of LLMs inside a malware command chain, letting intrusions run autonomously and raising the risk of crypto wallet theft.
Source: DiarioBitcoin