TL;DR
Cisco Talos has released an open-source malware classification framework called CAIRN and used it to identify CLOSEDQUORUM, a fully autonomous Windows malware that polls four LLMs simultaneously and requires zero human operators to function.
What happened
- Cisco Talos released CAIRN (Cognitive Artifact Intelligence Research Network) on September 22, 2026, an open-source framework for fingerprinting and classifying AI-integrated malware.
- CAIRN identified CLOSEDQUORUM, a Windows credential and cryptocurrency-stealing malware that queries DeepSeek, Qwen, Mistral, and Google Gemini in a consensus loop to decide its next moves.
- No human operator is required: CLOSEDQUORUM is fully redundant across four LLMs, so if one AI service goes offline, the others keep it running autonomously.
- Cisco Talos researcher Ryan Fetterman found only nine named AI-integrated malware families documented publicly before CAIRN; using the tool, he discovered roughly 20 additional examples.
- Links between CLOSEDQUORUM and cybercriminal forums focused on credit card fraud date to 2025, though attribution and confirmed real-world deployment remain unverified.
Why it matters
- Autonomous command-and-control is a threshold crossed: malware that governs itself through an LLM hive mind removes the human bottleneck attackers previously needed, enabling higher-volume, lower-cost campaigns.
- The true AI-malware landscape is broader than public reporting suggested: Fetterman's CAIRN-assisted survey found the field "a lot more complex and diverse" than the handful of cases previously known.
- AI integration leaves detectable fingerprints in metadata, meaning defenders now have a systematic way to track, tag, and cluster these samples before the category matures and hardens.
- Matt Olney, Cisco Talos senior director of threat intelligence, frames the shift as AI moving from productivity tool to operational attack infrastructure, letting adversaries run more campaigns across more targets simultaneously.
- The LAMEHUG precedent (flagged by Ukraine's CERT-UA in July 2025, using Qwen2.5-Coder-32B-Instruct via Hugging Face) showed the pattern was real; CAIRN now gives defenders a repeatable method to catch what comes next.
What to watch next
- Adoption of CAIRN by other threat-intelligence teams: if the framework becomes an industry standard, the collective library of tagged AI-malware samples will grow fast and sharpen early-warning signals.
- Whether CLOSEDQUORUM surfaces in confirmed attacks: Cisco Talos could not verify real-world deployment; a confirmed incident would mark the first publicly documented autonomous-LLM intrusion campaign.
- LLM provider responses: DeepSeek, Qwen, Mistral, and Google Gemini are all named as unwitting C2 infrastructure; watch for API abuse policies or detection measures aimed at blocking malware polling behavior.
Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.