78SECURITY
AI goes to war: malware that decides attacks, drones spread via cartels, and AI rules stall
A new Windows malware called ClosedQuorum is reported to use multiple generative AI models—including Google Gemini, DeepSeek, Qwen, and Mistral—to autonomously decide what actions to take during post-compromise stages of an intrusion. The reporting frames this as a shift from static playbooks toward adaptive decision-making inside compromised environments, raising the odds of faster, less predictable attacker behavior. In parallel, multiple pieces focus on how militaries are operationalizing AI and automation in lethal targeting and drone warfare, suggesting a broader “AI-to-hard-power” transition. Together, the cyber and battlefield narratives converge on one theme: decision loops are being shortened, and safeguards are struggling to keep pace.
Strategically, the cluster links three arenas that increasingly reinforce each other: cyber intrusion, drone-enabled battlefield competition, and diplomatic attempts to manage escalation. Brazil’s Lula used the UN General Assembly to renew support for a China-launched peace initiative on Ukraine, while also signaling dissatisfaction with US pressure and tariff dynamics, underscoring how middle powers are trying to shape narratives and outcomes. Meanwhile, analysis pieces argue that allies and major powers are rethinking espionage and intelligence tradecraft under Russian and Chinese pressure, and that the US-China AI regulatory gap could widen the security divide. The net effect is a multipolar contest where “rules” are contested as fiercely as “capabilities,” and where miscalculation risk rises when AI systems influence targeting, logistics, and even post-compromise cyber actions.
Market and economic implications are likely to concentrate in defense, cybersecurity, and AI infrastructure spending, with second-order effects on energy and industrial supply chains tied to wartime output. Cyber risk premia tend to rise when malware becomes more autonomous, which can lift demand for endpoint detection, incident response, and managed security services; investors typically watch names tied to identity security, SOC automation, and threat intelligence. On the defense side, drone warfare lessons and medical adaptation in China point to continued procurement of counter-drone systems, munitions, and battlefield medical technologies, while claims about strike effectiveness feed debates over cost-efficiency and future budgets. Currency and commodity impacts are less direct in the articles, but sustained Ukraine-related disruption and tariff rhetoric can keep volatility elevated in risk assets and in European industrial sentiment.
What to watch next is whether AI governance moves from principle to enforceable controls, especially as Xi’s US visit is framed as unlikely to deliver near-term AI regulation. In the near term, monitoring should focus on further disclosures about ClosedQuorum’s behavior, indicators of compromise, and whether defenders can reliably constrain its decision-making loops. On the military side, CENTCOM’s changes to AI and lethal targeting processes will be a key signal of how quickly safeguards are operationalized, while reporting on Russian drone strikes and Ukraine’s drone spending efficiency will inform escalation narratives. Finally, the diplomacy track—Lula’s UN push and China’s peace initiative—should be monitored for concrete follow-on steps, such as proposed frameworks, verification mechanisms, or timelines that could either reduce or harden positions before the next major escalation window.
Ver análisis