Interestana
Home/News/Windows Malware Uses AI Models to Vote on Attack Actions
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Windows Malware Uses AI Models to Vote on Attack Actions

Windows Malware Uses AI Models to Vote on Attack Actions

A novel Windows malware, identified as CLOSEDQUORUM, has been developed to operate by soliciting decisions from a collective of up to four artificial intelligence models, rather than relying on direct commands from a remote attacker's server. This unique approach was detailed by Cisco Talos in a report published on September 22. The AI models integrated into CLOSEDQUORUM are designed to collectively determine and execute malicious actions, which can include the exfiltration of sensitive user data. Specifically, these actions can involve stealing Windows credentials, harvesting saved browser passwords, and targeting cryptocurrency wallet data. This represents a significant evolution in malware design, moving towards decentralized, AI-driven decision-making for cyberattacks.

Cisco Talos has indicated that while the concept of this AI-driven malware has been observed, they have not yet witnessed a fully operational, end-to-end execution of CLOSEDQUORUM in the wild. Furthermore, the publicly available version of the malware, as analyzed by Talos, does not currently function as intended, suggesting it is either an early-stage development or a proof-of-concept. The implications of such malware, if fully realized, are substantial. Traditional malware relies on a direct communication channel between the infected machine and a command-and-control (C2) server controlled by the attacker. This C2 server issues instructions, and the malware executes them. By replacing or augmenting this C2 structure with AI models, CLOSEDQUORUM could potentially evade detection methods that focus on identifying communication with known malicious servers. The AI models, by voting on actions, introduce a layer of distributed intelligence that could make the malware's behavior more dynamic and harder to predict.

The potential for AI models to autonomously decide on attack vectors and targets raises new concerns for cybersecurity professionals. Instead of a human attacker manually directing each step of an intrusion, AI agents could be programmed to identify vulnerabilities, assess risks, and initiate actions based on their training and the collective output of the model ensemble. This could accelerate the pace of attacks and increase their sophistication. The ability of the AI to vote on actions means that a single malicious instruction might not be executed unless a consensus is reached among the AI models, potentially adding a layer of resilience or complexity to the malware's operation. The specific types of data targeted—credentials, browser passwords, and crypto wallet data—are among the most valuable for cybercriminals, indicating a focus on financial gain and identity theft.

Cisco Talos's analysis highlights the ongoing trend of attackers incorporating advanced technologies like artificial intelligence into their tools. The development of malware that can autonomously make decisions, even if currently in its nascent stages, signals a future where cyber threats could become more adaptive and challenging to defend against. The absence of a fully functional version in the wild, as reported by Talos, provides a window of opportunity for security researchers and organizations to study this emerging threat vector and develop countermeasures before it becomes widespread. The concept of AI models voting on malicious actions is a significant departure from current malware paradigms and underscores the need for continuous innovation in cybersecurity defenses to keep pace with evolving attack methodologies.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next