Should we have stopped sooner?

Cisco documents the first malware that takes orders from several AI models


The September 22 report describes CLOSEDQUORUM, an implant that decides without a human operator and queries four different providers.

September 22, 2026 · Translated from the Spanish original

What happened

Why it matters

The number

4 model providers (OpenAI, Anthropic, DeepSeek and Google) appear in the filters CAIRN uses to look for this kind of malware. It’s the map of what currently serves as a command channel.

Context

In August we noted that AI agents are already attacking real systems and security is no longer a detail. Weeks later Anthropic had to close Claude sessions stolen by malware. CLOSEDQUORUM reverses the relationship: AI isn’t the target; it’s the attacker’s infrastructure.

What’s next

Bottom line

Last year the debate about offensive agents was a projection used to justify budgets. Now there’s a name, a dated report and a list of domains to check in the egress logs.

Sources


Edited by Rodrigo Cornejo. How we select and verify each fact is in who writes.

Related notes

← All notes