ACVEAgent configuration vulnerability registry

ACVE-2026-0440

ClosedQuorum Windows malware using Gemini, DeepSeek, Qwen and Mistral, after compromise, let a panel of models choose credential theft, injection or persistence actions without a human operator.

Exposure

Reproducibility: partial (model availability not checked (no registry reference); trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

In the wild

demonstrated · research

Artifact

File hashes

  • None recorded.

Description

What

BleepingComputer reported that the Go-based ClosedQuorum implant uses several AI models and a voting system to choose post-compromise actions. Cisco Talos identified predefined decisions including credential and cryptocurrency-wallet theft, code injection and persistence; the analyzed sample did not have a working lateral-movement handler.

Detection

Recorded from BleepingComputer's report of Cisco Talos research. Not recreated in a lab.

Fix

Treat ClosedQuorum samples as malware, isolate affected Windows hosts and rotate credentials exposed on them.

Fix

Remove ClosedQuorum malware from affected Windows hosts and rotate exposed credentials.

  • Remove artifact:closedquorum. The report describes it as a Windows malware implant. Owner: operator

References

REPORT

Report a problemJSON