# Cisco Talos finds a Windows implant that asks four AI models to vote on its next move

> Cisco Talos documented CLOSEDQUORUM, a Windows implant where AI models vote on its next move, and built a tool, CAIRN, to find similar programs.

FireAI Security & Research Team (HisnLabs) · Published 2026-09-28
Canonical: https://hisnlabs.com/en/news/closedquorum-ai-voting-windows-implant

Cisco Talos, Cisco's threat-intelligence team, says it has documented what appears to be the first Windows implant that hands its next move to a panel of AI models instead of a human operator [[1]](https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/). Researcher Ryan Fetterman describes CLOSEDQUORUM, a 64-bit Windows program written in Go, in a report published 22 September 2026 [[1]](https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/).

## Background

Talos found CLOSEDQUORUM through CAIRN, a research toolkit it released the same day [[2]](https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/). CAIRN, short for Cognitive Artifact Intelligence Research Network, searches a program's code for the traces attackers leave when they wire AI into their tools: prompt text, the addresses of AI providers, API keys and jailbreak phrasing, found by reading code rather than running it [[2]](https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/).

## Findings

Talos is explicit about what it has and has not confirmed: the sample it examined ships with placeholder, non-working API keys, and the researchers say "we do not have confirmation of in-the-wild deployment," as BleepingComputer reported [[3]](https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/). That reads as a working proof-of-concept or template Talos caught while testing CAIRN, not a program confirmed to have been used against real victims.

CLOSEDQUORUM queries up to four AI providers, Google Gemini, DeepSeek, Qwen and Mistral, one after another, and asks each to vote on the next step from a fixed menu: steal (take saved passwords and cryptocurrency-wallet data), inject (run code inside another running program), persist (survive a reboot), or move (spread to another machine, an option Talos found did not work in the copies it examined) [[1]](https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/). Whichever action gets the most votes runs; a tie is settled by a fixed order, DeepSeek first, then Qwen, then Mistral, then Gemini, and results are posted to a Discord webhook, with no person in that loop [[1]](https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/). As Talos put it, "effort displacement compounds the effects of speed and scale because the human-in-the-loop is no longer the bottleneck" [[1]](https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/).

## Implications for Mac users

CLOSEDQUORUM is compiled to run on Windows only; it does not run on macOS, so this specific program is not something a Mac can be infected by, however it is opened or clicked. The pattern behind it applies on any computer: a program that has to keep asking an AI provider what to do next has to keep contacting that provider’s servers to get an answer, which produces a distinctive, visible shape on the network, repeated outbound calls to AI-model API endpoints with no obvious legitimate reason. That shape is a network fact rather than a Windows fact, and is often easier to notice from outside a program, by watching where it connects, than from inside it, by reading its code.

> See which apps on a Mac are already talking to an AI provider, and why. Test FireAI free for 17 days and see every outbound connection, app by app. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Recommendations

1. On Windows machines, keep the OS and endpoint protection current, and treat this less as a specific file to hunt for and more as a pattern other programs may copy.
2. On a Mac, get in the habit of checking which apps and background processes are making outbound connections, not just which apps were opened.
3. Treat an app repeatedly contacting AI-provider endpoints, such as api.openai.com, api.anthropic.com or generativelanguage.googleapis.com, as worth a second look if it has no obvious reason to be an AI client.
4. Judge a connection by where it actually goes, not by an app’s name or icon.
5. On a small office or family network, ask the same question about every device on it, not only the Macs.

## Relevance to FireAI

FireAI is a macOS app. It does not run on Windows and does nothing to protect a Windows PC from CLOSEDQUORUM or anything built like it; Windows machines on a household or office network need to be checked separately.

- [Investigate a connection](https://hisnlabs.com/en/docs/investigate-a-connection) builds a short dossier on any connection an app makes: no developer signature, a raw IP instead of a domain name, or the first time that app has contacted that destination.
- The [world map](https://hisnlabs.com/en/docs/world-map) shows which company and country an app’s traffic is actually going to, so a process quietly reaching an AI provider is not just another line in a log.
- [Per-app rules](https://hisnlabs.com/en/docs/per-app-rules) allow blocking a specific app, or a whole company’s infrastructure, once a destination is judged unwanted.
- [Threat-intelligence lists](https://hisnlabs.com/en/docs/threat-intelligence-feeds) check outbound connections once a day against opt-in public blocklists, and only block what one of those lists actually confirms.
- FireAI’s own on-device AI, [Ask FireAI](https://hisnlabs.com/en/docs/on-device-ai-model), runs locally on the Mac and never has to contact a cloud provider to reason about what it is looking at.

FireAI does not scan files, and does not detect or remove harmful software as code or as a behaviour sitting on disk; it would not recognise CLOSEDQUORUM by name or by file signature. What it provides is visibility into, and control over, where the apps on a Mac send data, which is what would surface this kind of pattern if something similar ever targeted a Mac.

> A program that has to keep asking an AI model what to do next has to keep calling home. FireAI shows a Mac’s network the same way, one connection at a time. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

Talos states plainly that it has no confirmation CLOSEDQUORUM has been deployed against a real target, so its practical impact so far is unknown [[3]](https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/). Neither Talos report specifies how the sample was obtained or how widely CAIRN has been run against other software, so it is not established how common this AI-voting pattern is beyond this one example [[1]](https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/) [[2]](https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/).

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [Cisco Talos (Ryan Fetterman), 22 September 2026: The Closed Quorum: Inside the first reported autonomous AI C2 implant](https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/)
- [Cisco Talos (Ryan Fetterman), 22 September 2026: Introducing CAIRN: Frontier tracking for AI-integrated malware](https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/)
- [BleepingComputer (Bill Toulas), 22 September 2026: New ClosedQuorum Windows malware uses AI for attack decisions](https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/)
