A novel malware strain discovered by researchers has weaponized commercial AI models, using them to autonomously vote on attack tactics without any human operator in the loop. The finding demands an urgent reassessment of enterprise defensive strategies.

Cisco Talos researchers have identified a Windows malware designated CLOSEDQUORUM, as reported by Security Affairs. The malware operates through a distinct, autonomous workflow. After initial reconnaissance on a compromised host, CLOSEDQUORUM sends data to four separate large language models (LLMs) and queries them for recommended next steps. The models' outputs are aggregated as votes, and the malware executes the majority-recommended action, such as exfiltrating specific data.

This mechanism marks a clear evolution beyond traditional command-and-control (C2) infrastructure. Rather than relying on a human attacker to issue directives from a server, CLOSEDQUORUM delegates strategic decision-making to an autonomous committee of AI services. This design creates adaptive, resilient, and unpredictable behavior, as the malware can dynamically alter its actions based on the consensus of its AI models.

For security teams — including those in Hong Kong's enterprise landscape — this presents immediate defensive challenges. Signature-based detection tools are largely ineffective against this operational approach. Defenses must pivot toward monitoring for behavioral anomalies. Priority indicators include unusual outbound API traffic to known AI service providers and irregular data-access requests initiated by endpoint processes showing no other signs of compromise.

Furthermore, CLOSEDQUORUM exposes a critical dual accountability in AI security. AI service providers must bolster real-time abuse detection to prevent their platforms from being co-opted as attack infrastructure. Simultaneously, organizations must proactively audit their own environments, securing AI API usage policies to eliminate the risk of unauthorized "shadow AI" connections that malware like this could exploit.

The discovery transitions AI-augmented attacks from a theoretical research concept to a deployed operational capability. The identity of the threat actor and the full scope of CLOSEDQUORUM's deployment remain unknown, but the analysis underscores this represents a new paradigm in automated threats. Security professionals are advised to treat this as an active and evolving model, and to immediately review defensive postures against autonomous, AI-driven malicious activity.


研究人員發現一種新型惡意軟件已將商業人工智能模型武器化,利用其在無需人為操作介入的情況下,自主投票決定攻擊戰術。這項發現要求企業緊急重新評估其防禦策略。

根據 Security Affairs 報導,Cisco Talos 研究人員識別出一款名為 CLOSEDQUORUM 的 Windows 惡意軟件。該惡意軟件透過獨特的自主工作流程運作。在對受感染主機進行初步偵察後,CLOSEDQUORUM 會將數據發送至四個獨立的大型語言模型,並查詢它們建議的下一步行動。模型輸出結果會被彙總為投票,惡意軟件則執行大多數模型推薦的行動,例如竊取特定數據。

此機制標誌著傳統指揮與控制基礎架構的明確演進。CLOSEDQUORUM 不再依賴人類攻擊者從伺服器發出指令,而是將戰略決策委託給一個由人工智能服務組成的自主委員會。這種設計創造了適應性強、具韌性且不可預測的行為模式,因為惡意軟件能根據其人工智能模型的共識動態調整行動。

對安全團隊——包括香港企業環境中的團隊——而言,這帶來了即時的防禦挑戰。基於特徵碼的檢測工具對此種操作模式基本無效。防禦措施必須轉向監控行為異常。優先關注的指標包括:指向已知人工智能服務供應商的異常外部 API 流量,以及由端點進程發起且無其他受感染跡象的異常數據訪問請求。

此外,CLOSEDQUORUM 暴露了人工智能安全中關鍵的雙重責任問題。人工智能服務供應商必須加強實時濫用檢測,防止其平台被徵用為攻擊基礎設施。同時,組織必須主動審計自身環境,確保人工智能 API 使用政策的安全,以消除類似惡意軟件可能利用的未授權「影子人工智能」連接風險。

這項發現將人工智能輔助攻擊從理論研究概念轉變為已部署的操作能力。儘管威脅行為者的身份及 CLOSEDQUORUM 部署的完整規模仍未知,但分析強調這代表自動化威脅的新範式。建議網絡安全專業人員將此視為一個活躍且持續演變的模式,並立即審查防禦姿態,以應對自主驅動的人工智能惡意活動。

新聞來源 / Original News Source