New ClosedQuorum Windows malware uses AI for attack decisions
Summary
A new Windows malware, dubbed ClosedQuorum, has been identified that leverages multiple AI models, including Google Gemini, DeepSeek, Qwen, and Mistral AI, to make autonomous decisions during the post-compromise stages of an attack. This allows the malware to adapt its actions and potentially evade detection.
IFF Assessment
The use of AI by malware to make autonomous decisions during attacks represents an advancement in threat capabilities, posing a greater challenge to defenders.
Defender Context
This development highlights the growing trend of threat actors incorporating AI into their toolkits, enabling more sophisticated and adaptive attacks. Defenders should be aware of AI-powered malware and the potential for autonomous decision-making to complicate incident response and detection efforts.