A new Windows malware named CLOSEDQUORUM has been identified, which reportedly utilises artificial intelligence models to autonomously determine actions following a system compromise. This malware is described as the first publicly documented Windows implant to employ large language models (LLMs) for command and control (C2).
The use of AI models allows CLOSEDQUORUM to select its post-compromise actions without direct human intervention, marking a notable development in malware capabilities.