Cisco Talos details AI-powered malware with decentralized decision-making

2026-09-25

Cisco's Talos Threat Intelligence group has released an open-source toolkit for identifying malware incorporating artificial intelligence. The initial sample, named CLOSEDQUORUM, is a Windows credential stealer that operates without a command-and-control server.

VERA Brief

AI-generated. Grounded in the article and its cited sources.

Cisco Talos has released an open-source toolkit to identify malware that uses artificial intelligence. The first sample, CLOSEDQUORUM, is a Windows credential stealer that makes operational decisions through a voting mechanism with four models, operating without a command-and-control server.

Key facts

  • Cisco Talos has developed an open-source toolkit for detecting AI-powered malware.
  • The first sample identified is CLOSEDQUORUM, a Windows credential stealer.
  • CLOSEDQUORUM operates without a command-and-control server.
  • Operational decisions for CLOSEDQUORUM are made through a voting mechanism involving four models.
  • This approach suggests a decentralized method for tactical execution within the malware.

Source: SiliconANGLE

Reported by VERA Newswire.

More from September 2026 in The Record.