TL;DR
Cisco Talos has released an open-source malware classification framework and used it to uncover CLOSEDQUORUM, a Windows hacking tool that polls four AI models simultaneously to autonomously direct its own attacks.
What happened
- Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network) on September 22, 2026, an open-source framework for detecting and classifying AI-integrated malware by its digital fingerprints.
- CLOSEDQUORUM, discovered via CAIRN, is Windows malware that queries DeepSeek, Qwen, Mistral, and Google Gemini in parallel to form a consensus on its next moves, with no human operator in the loop.
- The malware is fully redundant: if one AI service goes offline, it polls the remaining three, making the command-and-control infrastructure self-sustaining.
- CLOSEDQUORUM is designed to steal login credentials and cryptocurrency, with links to cybercriminal forums discussing credit card fraud dating to 2025.
- CAIRN has so far catalogued roughly 29 named AI-integrated malware families, up from the 9 publicly documented examples researcher Ryan Fetterman found before building the tool.
Why it matters
- Agentic malware removes the human bottleneck: attackers can run more campaigns across more targets because an AI backend handles real-time decision-making, per Cisco Talos senior director Matt Olney.
- The hive-mind architecture is a structural leap: no single AI provider can neutralize the threat by cutting off access, and there is no command channel for defenders to sinkhole.
- AI integration leaves detectable metadata artifacts, meaning CAIRN-style fingerprinting could become as foundational to threat intelligence as signature-based detection, but only if the security community adopts a shared taxonomy fast.
- The gap between public reporting and actual prevalence is significant: Fetterman found 20 previously undocumented examples in just a few months, suggesting the threat is more mature than the industry believed.
- CERT-UA flagged the precursor LAMEHUG in July 2025, using Qwen2.5-Coder-32B-Instruct via Hugging Face API, showing a clear evolutionary line from single-model implants to multi-model autonomous systems.
What to watch next
- CAIRN adoption rate across the security community will determine whether this becomes a shared intelligence layer or a Cisco-only advantage.
- Attribution of CLOSEDQUORUM: Cisco Talos has not confirmed a threat actor or confirmed real-world deployment, so the first confirmed attack campaign using this architecture is the critical escalation signal.
- AI provider responses: whether DeepSeek, Mistral, Google, and Alibaba (Qwen) implement API-level controls to detect and block malware polling will shape how quickly attackers are forced to self-host models instead.
Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.