presentofai

Cisco Talos releases CAIRN framework, identifies autonomous AI-guided malware

TL;DR

Cisco Talos has released an open-source malware classification framework called CAIRN and used it to identify CLOSEDQUORUM, a fully autonomous Windows malware that polls four LLMs simultaneously and requires zero human operator input.

What happened

  • Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network) on September 23, 2026, an open-source framework to fingerprint and classify AI-integrated malware.
  • CLOSEDQUORUM, discovered via CAIRN, is Windows malware that queries DeepSeek, Qwen, Mistral, and Google Gemini in a consensus loop to decide its next moves inside a target system.
  • The malware has no human command-and-control mechanism: if one LLM is unavailable, it polls the remaining three, maintaining full autonomy.
  • CLOSEDQUORUM is designed to steal login credentials and cryptocurrency, with links to cybercriminal forums about credit card fraud dating to 2025.
  • Before CAIRN, Cisco Talos researcher Ryan Fetterman could document only 9 named AI-integrated malware families publicly; CAIRN has since surfaced roughly 20 additional examples.

Why it matters

  • Fully autonomous malware with no human operator is a qualitative escalation: defenders can no longer rely on disrupting a human controller to stop an attack.
  • The hive-mind redundancy model (four LLMs, consensus-driven) makes the system resilient to API outages and harder to neuter by blocking a single AI provider.
  • AI-integrated malware is more widespread than public reporting suggests, per Fetterman: the landscape is "a lot more complex and diverse" than the handful of documented cases implied.
  • The July 2025 LAMEHUG campaign (flagged by Ukraine's CERT-UA) used Qwen2.5-Coder-32B-Instruct via Hugging Face API for commands, showing nation-adjacent actors already operationalizing LLM-driven implants.
  • As Cisco Talos senior director Matt Olney frames it, AI is shifting from productivity tool to operational force multiplier for attackers, enabling more campaigns across more targets with less human overhead.

What to watch next

  • Whether other security vendors adopt CAIRN as a shared classification standard, which would determine how quickly the defensive community builds a comprehensive AI-malware threat map.
  • Confirmation of real-world CLOSEDQUORUM deployments: Cisco Talos has not yet verified active use, so attribution and victim identification are the critical next data points.
  • Emergence of LLM-provider responses: whether DeepSeek, Mistral, Google, and Alibaba's Qwen teams implement API controls to detect and block malware polling patterns.

Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.