Talos: CLOSEDQUORUM malware lets four LLMs vote on next attack step
Cisco Talos documented CLOSEDQUORUM, a Windows credential stealer that asks DeepSeek, Qwen, Gemini, and Mistral what to do next and follows the majority vote—no attacker C2 server to block. The public binary is an inert template with placeholder API keys; Talos has not confirmed live victims.