Cisco Talos finds malware that puts its next move to a four-model vote
Cisco discovered malware that votes among four AI models to decide its next move — no command server needed.

Why it matters
AI-powered autonomous malware represents a novel attack surface: distributed decision-making agents that operate without traditional C2 infrastructure, forcing security teams to think about agent reliability and exploitation differently.
The key facts
5 to knowMalware named CLOSEDQUORUM uses four-model voting mechanism for tactical decisions
No command-and-control server required — decisions made autonomously by model ensemble
Cisco Talos released open-source toolkit for AI-powered malware hunting
Windows credential stealer as proof-of-concept sample
September 2026 discovery/disclosure date
Go to the source
SiliconAnglesiliconangle.com
Publisher excerpt: Cisco Systems Inc.’s Talos Threat Intelligence group today released an open-source toolkit for hunting malware that has artificial intelligence built into it. The first sample it has detailed is a Windows credential stealer that takes its orders from no command-and-control server. Talos calls it…
