What CAIRN found
Security teams have long used digital fingerprints to recognize hacking tools, track samples and study how they change. CAIRN applies that logic to AI integration, looking for traces in malware metadata and assigning samples effectively unique identifiers.
The framework then compares each artifact with the rest of its library. That makes it possible to group samples, identify possible links and detect patterns that would be difficult to see in isolated investigations.
The immediate result is larger than the public record suggested. In a retrospective analysis, Ryan Fetterman, a Cisco Talos security researcher and CAIRN's development lead, found around nine previously named malware families with AI integration. Some were research demonstrations rather than operational criminal tools. Over several months of using CAIRN, he identified about 20 additional examples.
Fetterman had expected the number of AI-enabled malware programs to rise sharply after CERT-UA described LAMEHUG in July 2025. That implant used the Hugging Face API to contact Qwen2.5-Coder-32B-Instruct and receive commands. Instead, a year later, he found only a small number of documented cases.
The result is a useful correction to the headline version of the trend: AI use by attackers is still largely experimental, but the underlying activity is more varied than published examples indicate.
CLOSEDQUORUM's model committee
CAIRN uncovered CLOSEDQUORUM, a Windows malware program that consults several AI services before deciding what to do inside a compromised system.
It contacts:
If one service is unavailable, CLOSEDQUORUM continues querying the others. That redundancy allows the program to operate without a human mechanism for entering commands, making its decision-making process effectively closed to direct operator input.
Cisco Talos found possible links between the malware and cybercrime forums where payment-card fraud had been discussed since 2025. CLOSEDQUORUM is designed to steal credentials and cryptocurrency.
The researchers could not confirm who built it or whether it had been used in real attacks. That missing evidence matters. A malware sample capable of autonomous decisions is not the same thing as a proven campaign, and the announcement does not establish how often the program has operated outside a laboratory or development environment.
From assistant to infrastructure
Matt Olney, senior director of threat analysis at Cisco Talos, described a shift in how attackers use AI. It began as a productivity tool for legitimate and malicious work, he said, but is becoming operational infrastructure: a background system that can help attackers run more campaigns, reach more targets, interact with more computers and answer questions as operations unfold.
My read is that CAIRN's most important contribution is not discovering a single autonomous malware family. It is giving researchers a way to separate an isolated proof of concept from a developing pattern. The roughly nine known families looked sparse; the 20 additional examples suggest that the scarcity was partly a visibility problem.
What I'd want to know next is not simply which models a sample can call, but whether those calls improve an attack enough to justify the added complexity. Talos has shown that malware can assemble a committee of models. It has not shown that the committee is reliable, widely deployed or useful in real campaigns.
That tension defines the current moment: AI is already appearing as infrastructure inside malicious software, while the evidence for a mature AI-powered threat market remains thin.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X