Bottom line: CLOSEDQUORUM Windows malware exploits AI models for evasion and credential theft.
What's happening: Cisco Talos reported that CLOSEDQUORUM uses up to four AI models to decide its next action, including stealing Windows credentials, saved browser passwords, and crypto wallet data. This malware targets Windows systems running Windows 10, designed by Google, with an estimated release date in mid-2021.
What to do: Security leaders should update Windows systems to version 21H2, which includes enhanced security features to mitigate CLOSEDQUORUM's capabilities. Additionally, enable Windows Defender Advanced Threat Protection to monitor for suspicious activity.