Lily Hay Newman over at Wired has an interesting report on an apparently autonomous hacking tool dubbed CLOSEDQUORUM, citing an investigation by Cisco Talos. The command-and-control infrastructure polls four LLMs (DeepSeek, Qwen, Mistral, and Google Gemini) to develop a consensus on what to do next.
The tool, as discovered by researchers, was non-functional, populated only with dummy values for the LLM API keys and Discord key (stolen credentials would be forwarded to said Discord server). The binary they analyzed traces back to posts made in 2025 by a user of a forum dedicated to stolen credit cards.
No in-the-wild deployment has so far been confirmed, but we can be pretty sure that autonomous cybercrime tools like this will start popping up soon.
