GMAsia
    AI News·23 Sept 2026·via Tweak Town

    Researchers found malware that lets AI models vote on how to attack you

    Researchers identified malware called CLOSEDQUORUM that exploits multiple AI models to coordinate attacks. The malware queries four distinct AI services: DeepSeek, Qwen, Mistral, and Google Gemini. It then selects an action based on which option receives the most votes from these models. This process allows the malware to leverage diverse AI perspectives for its operational decisions.

    Nexa's Summary

    Malware now weaponizes AI model diversity, not just individual models. CLOSEDQUORUM uses four different LLMs, including DeepSeek and Qwen, to 'vote' on attack strategies. This collective decision-making makes the malware more adaptive and resilient to single-model defenses, a new vector for AI-powered threats.

    For Asia, this points to a new challenge for model developers and cybersecurity firms. Chinese firms like DeepSeek and Qwen are now part of a threat vector. Regulators in Singapore and South Korea will need to consider how to mandate security standards for AI services that could be exploited in this way. The onus is on developers to harden APIs against such query-based attacks.

    The thing to watch is whether this 'voting' mechanism scales to more models or more complex attack types. If future malware incorporates ten or twenty models, defense becomes exponentially harder. The test for major Asian cloud providers is how quickly they can detect and mitigate these multi-model query patterns.

    #google#deepseek#windows malware#cisco talos#mistral#qwen#process hollowing#google gemini#closedquorum#credential dumping
    Original reporting by Tweak TownWe don't republish, read the full story →

    Related reading

    6 stories