Last seen September 23, 2026

Claude Credential Exposure

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

Technical Severity
Low severity
Lifecycle Status

NEW

What Happened

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

Why This Matters

The evidence matters to defenders using Claude because it may expose credentials or secrets available to affected workloads.

Recommended Action

No confirmed vendor remediation is available in the current evidence. Confirm whether Claude is present in your environment and review the affected configuration.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Sep 23, 2026 19:47

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

AnthropicGoogleOpenAIClaudeGeminiCredential Exposure

Timeline

  • Incident first seen
    Sep 23, 2026 19:47

    BugSkan first recorded this incident.

  • This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
    Sep 23, 2026 19:47

    thehackernews.com · Research

Sources

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

thehackernews.com · Sep 23, 2026 19:47

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence