presentofai

Cisco Talos finds AI hive-mind malware with no human operators

TL;DR

Cisco Talos has released an open-source malware classification framework called CAIRN and used it to identify CLOSEDQUORUM, a fully autonomous Windows malware that polls four LLMs simultaneously and requires zero human operators.

What happened

  • Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network) on September 22, 2026, an open-source framework for detecting and classifying AI-integrated malware by its digital fingerprints.
  • CLOSEDQUORUM, discovered via CAIRN, is Windows malware that queries DeepSeek, Qwen, Mistral, and Google Gemini in a consensus loop to decide its next moves, with no human command-and-control channel.
  • The malware is designed to steal login credentials and cryptocurrency, with links to cybercriminal forums discussing credit card fraud dating to 2025.
  • CAIRN lead researcher Ryan Fetterman found only nine named AI-integrated malware families in public documentation before building the tool; CAIRN has since surfaced roughly 20 additional examples.
  • A July 2025 Ukrainian CERT-UA warning about LAMEHUG, which used the Qwen2.5-Coder-32B-Instruct model via Hugging Face API, was an early signal that prompted the research.

Why it matters

  • No human operator required: CLOSEDQUORUM's multi-LLM redundancy means takedown of any single AI service does not disable the malware, a structural resilience leap over traditional C2 infrastructure.
  • The AI-integration fingerprint concept is the key defensive unlock: CAIRN treats LLM API calls, metadata artifacts, and behavioral patterns as trackable signatures, the same way hashes track conventional malware.
  • Cisco Talos senior director Matt Olney frames the shift as AI moving from productivity tool to operational infrastructure for attackers, enabling higher campaign volume and broader target coverage.
  • The landscape is more complex than publicly reported: Fetterman's own surprise at finding 20-plus undocumented examples suggests the defensive community is behind the curve on cataloguing the threat.
  • CLOSEDQUORUM's financial targeting (credentials, crypto) signals organized cybercrime, not nation-state experimentation, lowering the barrier for who can deploy autonomous AI malware.

What to watch next

  • CAIRN adoption across the security community: the framework is open-source, so uptake speed among vendors and CERTs will determine how quickly the fingerprint library scales.
  • Attribution of CLOSEDQUORUM: Cisco Talos could not confirm the developer or confirm real-world deployment; confirmation of active use would mark a threshold moment for autonomous AI malware in the wild.
  • LLM provider responses: if AI services like DeepSeek, Mistral, and Gemini become recognized C2 channels, expect policy and API-abuse detection pressure on those platforms.

Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.