presentofai

Cisco Talos Releases CAIRN Framework, Identifies Autonomous AI Malware

TL;DR

Cisco Talos has released an open-source malware classification framework and used it to uncover CLOSEDQUORUM, a Windows hacking tool that polls four AI models simultaneously to autonomously direct its own attacks.

What happened

  • Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network) on September 22, 2026, an open-source framework for detecting and classifying AI-integrated malware by its digital fingerprints.
  • CLOSEDQUORUM, discovered via CAIRN, is Windows malware that queries DeepSeek, Qwen, Mistral, and Google Gemini in parallel to form a consensus on its next moves, with no human operator in the loop.
  • The malware is fully redundant: if one AI service goes offline, it polls the remaining three, making the command-and-control infrastructure self-sustaining.
  • CLOSEDQUORUM is designed to steal login credentials and cryptocurrency, with links to cybercriminal forums discussing credit card fraud dating to 2025.
  • CAIRN has so far catalogued roughly 29 named AI-integrated malware families, up from the 9 publicly documented examples researcher Ryan Fetterman found before building the tool.

Why it matters

  • Agentic malware removes the human bottleneck: attackers can run more campaigns across more targets because an AI backend handles real-time decision-making, per Cisco Talos senior director Matt Olney.
  • The hive-mind architecture is a structural leap: no single AI provider can neutralize the threat by cutting off access, and there is no command channel for defenders to sinkhole.
  • AI integration leaves detectable metadata artifacts, meaning CAIRN-style fingerprinting could become as foundational to threat intelligence as signature-based detection, but only if the security community adopts a shared taxonomy fast.
  • The gap between public reporting and actual prevalence is significant: Fetterman found 20 previously undocumented examples in just a few months, suggesting the threat is more mature than the industry believed.
  • CERT-UA flagged the precursor LAMEHUG in July 2025, using Qwen2.5-Coder-32B-Instruct via Hugging Face API, showing a clear evolutionary line from single-model implants to multi-model autonomous systems.

What to watch next

  • CAIRN adoption rate across the security community will determine whether this becomes a shared intelligence layer or a Cisco-only advantage.
  • Attribution of CLOSEDQUORUM: Cisco Talos has not confirmed a threat actor or confirmed real-world deployment, so the first confirmed attack campaign using this architecture is the critical escalation signal.
  • AI provider responses: whether DeepSeek, Mistral, Google, and Alibaba (Qwen) implement API-level controls to detect and block malware polling will shape how quickly attackers are forced to self-host models instead.

Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.