CORTEXFLOW · FREE FOREVER

News

CLOSEDQUORUM: Cisco Talos Found Malware That Asks Four AI Models to Vote Before It Attacks

CLOSEDQUORUM: Cisco Talos Found Malware That Asks Four AI Models to Vote Before It Attacks
FIG. 01 — CLOSEDQUORUM: Cisco Talos Found Malware That Asks Four AI Models to Vote Before It AttacksSCALE 16:9

Multi-agent architectures have a dark side now. Cisco Talos researchers have released CAIRN, an open-source framework for identifying and classifying malware that incorporates artificial intelligence — and the first major find using it is CLOSEDQUORUM: Windows malware that polls four different AI models — DeepSeek, Qwen, Mistral, and Google Gemini — and only acts when they reach consensus. It is designed to steal login credentials and cryptocurrency. If you build multi-agent systems in n8n or anywhere else, this is the attack pattern you need to understand this week.

The reporting comes from Cisco Talos research summarized in the October 2, 2026 AI news roundup. The details are still thin, but the shape of the finding is clear — and it says something important about where agent security is heading.

What Cisco Talos found

CAIRN is a classification framework, not a single detection tool. Talos built it to answer a question the industry couldn’t answer before: how do you systematically tell whether malware is “AI-powered” versus just regular malware with a chatbot glued on? The framework gives researchers a shared vocabulary for AI-incorporated malware, and it’s open source.

The headline catch from running CAIRN against real samples: CLOSEDQUORUM, a Windows malware family that doesn’t ask a human operator what to do next. Instead, it queries four different frontier models — DeepSeek, Qwen, Mistral, and Google Gemini — and acts on what they agree on. The malware’s stated goals are credential theft and crypto theft.

One detail worth respecting: Talos researchers could not confirm who built it or whether it has been used in real-world attacks. Treat this as a discovered capability, not a confirmed campaign. CAIRN has surfaced roughly 20 additional examples of AI-integrated malware so far, which suggests this activity is experimental but more diverse than previously documented.

How AI-consensus malware works

A consensus architecture means the malware doesn’t trust a single model. It asks several models the same operational question — what should I do next on this machine — and proceeds with what the majority (or the weighted agreement) supports.

Think about why an attacker would build it this way. A single-model agent can be derailed by one model’s refusal, hallucination, or degraded output. Four models voting against each other produces a crude but effective error correction: if DeepSeek refuses a malicious instruction but Gemini complies, the disagreement is itself information. The attacker is borrowing the exact reliability trick that legitimate agent builders use — redundancy across models reduces single-point-of-failure risk — and applying it to payload decisions.

Close-up of a padlock on a laptop keyboard — the first line of defense is your own machine

This is also a defense-evasion story. Traditional malware signatures key off code patterns and command-and-control traffic. When the “brain” of the operation lives inside API calls to public AI services, the malicious logic isn’t in the binary for an antivirus to fingerprint — it emerges at runtime from the models’ answers. The implant on disk can be small, generic, and hard to attribute.

Why this architecture is hard to defend against

Three properties make consensus-driven malware worse than the single-model kind that came before it:

1. Model-level safety becomes irrelevant. Each individual model’s safety alignment (the refusal behavior vendors train in) is just one vote. The malware doesn’t need any single model to say yes — it needs enough of them to agree, or to route around refusals by rephrasing. Distributed refusal is a fundamentally harder problem than single-model refusal.

2. The behavior is non-deterministic. The same binary can make different decisions on different runs depending on model outputs that shift over time. That breaks the analysis pipeline that defenders rely on: run it in a sandbox, watch what it does, write a rule. If run two disagrees with run one, your rule is stale.

3. Attribution gets murkier. When operational decisions are generated by public models, the malware carries no operator’s fingerprint in its logic — no custom exploit, no recognizable C2 protocol pattern. The code is a shell; the intelligence is rented.

Note: don’t over-read the findings. This is one discovered family plus ~20 additional samples of AI-integrated malware of various kinds — not proof that consensus-driven malware is widespread. The honest reading: the technique exists, it works well enough to be worth building, and it will be copied.

What this means for agent builders

You don’t build malware. But you build the same machinery, and the same machinery has the same failure modes. CLOSEDQUORUM is a mirror held up to legitimate multi-agent design, so take the lessons it offers:

  • Audit what your agents can ask models to do. If your n8n AI Agent has a code-execution tool, a shell tool, or credentials in its context window, that is the same attack surface CLOSEDQUORUM lives on — the model is the decision layer. Limit tools to the minimum the task needs.
  • Consensus is not safety. A committee of models agreeing on an action feels safer than one model deciding. It isn’t — it just means the error has to survive a vote. Human approval gates (the kind Pricelabs’ Athena popularized) are still the only backstop that doesn’t share the agents’ failure modes.
  • Your API keys are the new C2 channel. CLOSEDQUORUM’s design implies the attacker’s money goes to model API bills. In your stack, a leaked LLM API key or MCP credential isn’t just a cost problem — it’s the credential that lets someone else run an autonomous agent on your account. Rotate keys, scope them, and log every call.
  • Watch for the legitimate-tool dual use. Everything CLOSEDQUORUM does — polling models, parsing their answers, executing shell commands — is a subset of what an n8n workflow does. Your own infrastructure is the attacker’s template. Keep workflow credentials in a vault (n8n’s credential store, not in node parameters), and treat any agent with network access as a trust boundary.

The larger point: Talos built CAIRN because the industry had no systematic way to track AI in malware. Builders should build the same discipline for their own agents — an inventory of what each agent can do, which models it can reach, and what it is not allowed to decide. Most teams can’t produce that list today. That’s the gap the attackers are walking through.

Key Takeaways

  1. Cisco Talos released CAIRN, an open-source framework for classifying AI-integrated malware — the first systematic tool for tracking this category.
  2. CLOSEDQUORUM is the headline find: Windows malware that polls DeepSeek, Qwen, Mistral, and Gemini for consensus on its next actions, targeting credentials and crypto.
  3. Consensus is redundancy, not safety — multiple models voting makes single-model refusals irrelevant and non-deterministic behavior breaks sandbox analysis.
  4. The creator and real-world use are unconfirmed — treat this as a proven technique, not a confirmed campaign, and don’t inflate the threat.
  5. Audit your own agents the way Talos audits malware — inventory every agent’s tools, model access, and decision authority, because your architecture and the attacker’s share the same failure modes.

Next step: pick your most privileged agent — the one with the most tools and the broadest credentials — and write down what it is allowed to decide on its own. If the list surprises you, that’s your Monday task.

Images: Unsplash

DOC. CF-RSS-001 · FORMAT: XML

Want more like this?

Practical tutorials on AI agents, automation, and chatbots — straight to your reader.

Subscribe via RSS

Doc. CF-NL-001 · Dispatch

Get the next build in your inbox

One practical email per new post. No spam, unsubscribe anytime.

One email per new post. No spam. Unsubscribe anytime.