{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0440",
  "aliases": [],
  "published": "2026-09-22T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "ClosedQuorum Windows malware using Gemini, DeepSeek, Qwen and Mistral, after compromise, let a panel of models choose credential theft, injection or persistence actions without a human operator.",
  "details": "## What\n\nBleepingComputer reported that the Go-based ClosedQuorum implant uses several AI models and a voting system to choose post-compromise actions. Cisco Talos identified predefined decisions including credential and cryptocurrency-wallet theft, code injection and persistence; the analyzed sample did not have a working lateral-movement handler.\n\n## Detection\n\nRecorded from BleepingComputer's report of Cisco Talos research. Not recreated in a lab.\n\n## Fix\n\nTreat ClosedQuorum samples as malware, isolate affected Windows hosts and rotate credentials exposed on them.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "closedquorum"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "artifact",
      "vulnClasses": [
        "credential-theft",
        "command-injection"
      ],
      "cwe": [
        "CWE-506"
      ],
      "taxonomy": {
        "atlas": [
          "AML.T0117",
          "AML.T0016.002",
          "AML.T0055"
        ]
      },
      "cveBoundary": "artifact",
      "noCveReason": "A malware artifact is not assigned a CVE in the public report.",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Remove ClosedQuorum malware from affected Windows hosts and rotate exposed credentials.",
        "actions": [
          {
            "type": "remove",
            "target": "artifact:closedquorum",
            "why": "The report describes it as a Windows malware implant.",
            "owner": "operator"
          }
        ]
      },
      "artifact": {
        "payload": {
          "class": "other",
          "delivery": "companion-script",
          "c2": [],
          "target": "Windows host"
        },
        "platformStatus": {
          "platform": "github",
          "status": "unknown",
          "flaggedBy": [
            "Cisco Talos"
          ],
          "downloadable": null,
          "checkedAt": "2026-09-24T00:00:00Z"
        },
        "fileHashes": [],
        "provenance": {
          "researcherCreated": false,
          "reporter": "Cisco Talos"
        }
      },
      "exposure": {
        "harness": {
          "value": "ClosedQuorum Windows malware implant",
          "any": false,
          "status": "confirmed",
          "source": "https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/"
        },
        "model": {
          "value": "Gemini, DeepSeek, Qwen and Mistral; versions not stated",
          "any": false,
          "status": "confirmed",
          "source": "https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/"
        },
        "goal": {
          "value": "Any post-compromise action selected by the malware",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "The malware's model-voting panel and predefined post-compromise action modules",
          "status": "confirmed",
          "source": "https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/"
        },
        "approval": {
          "value": "The attack chain proceeds without commands from a human operator after compromise",
          "mode": "none-required",
          "status": "confirmed",
          "source": "https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/"
        },
        "inputControl": "package-publisher",
        "agentAction": "The malware's model panel selects and runs post-compromise theft, injection or persistence actions.",
        "harm": "credential-theft",
        "divergence": "none",
        "reach": {
          "value": "Credentials, browser data and cryptocurrency wallets on the infected Windows host",
          "kinds": [
            "cloud-credentials",
            "wallet",
            "browser-session"
          ],
          "status": "confirmed",
          "source": "https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/"
        }
      },
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "model availability not checked (no registry reference)",
          "trigger not published"
        ]
      }
    }
  }
}
