i
News
News · 2026-09-22

Cisco Talos finds AI-run malware with CAIRN

@neuronium_ai @neuronium_ai

Cisco Talos has introduced CAIRN, a framework for identifying and classifying malware that uses AI. The system has already uncovered CLOSEDQUORUM, a Windows program that asks multiple AI models to agree on what to do next inside an infected machine. The discovery matters less as proof of a mature criminal ecosystem than as evidence that AI-driven malware may be easier to miss when researchers examine samples one at a time.

Cover: Cisco Talos finds AI-run malware with CAIRN

What CAIRN found

Security teams have long used digital fingerprints to recognize hacking tools, track samples and study how they change. CAIRN applies that logic to AI integration, looking for traces in malware metadata and assigning samples effectively unique identifiers.

The framework then compares each artifact with the rest of its library. That makes it possible to group samples, identify possible links and detect patterns that would be difficult to see in isolated investigations.

The immediate result is larger than the public record suggested. In a retrospective analysis, Ryan Fetterman, a Cisco Talos security researcher and CAIRN's development lead, found around nine previously named malware families with AI integration. Some were research demonstrations rather than operational criminal tools. Over several months of using CAIRN, he identified about 20 additional examples.

9previously named families
20additional examples

Fetterman had expected the number of AI-enabled malware programs to rise sharply after CERT-UA described LAMEHUG in July 2025. That implant used the Hugging Face API to contact Qwen2.5-Coder-32B-Instruct and receive commands. Instead, a year later, he found only a small number of documented cases.

The result is a useful correction to the headline version of the trend: AI use by attackers is still largely experimental, but the underlying activity is more varied than published examples indicate.

CLOSEDQUORUM's model committee

CAIRN uncovered CLOSEDQUORUM, a Windows malware program that consults several AI services before deciding what to do inside a compromised system.

It contacts:

DeepSeek
Qwen
Mistral
Google Gemini

If one service is unavailable, CLOSEDQUORUM continues querying the others. That redundancy allows the program to operate without a human mechanism for entering commands, making its decision-making process effectively closed to direct operator input.

Cisco Talos found possible links between the malware and cybercrime forums where payment-card fraud had been discussed since 2025. CLOSEDQUORUM is designed to steal credentials and cryptocurrency.

The researchers could not confirm who built it or whether it had been used in real attacks. That missing evidence matters. A malware sample capable of autonomous decisions is not the same thing as a proven campaign, and the announcement does not establish how often the program has operated outside a laboratory or development environment.

From assistant to infrastructure

Matt Olney, senior director of threat analysis at Cisco Talos, described a shift in how attackers use AI. It began as a productivity tool for legitimate and malicious work, he said, but is becoming operational infrastructure: a background system that can help attackers run more campaigns, reach more targets, interact with more computers and answer questions as operations unfold.

My read is that CAIRN's most important contribution is not discovering a single autonomous malware family. It is giving researchers a way to separate an isolated proof of concept from a developing pattern. The roughly nine known families looked sparse; the 20 additional examples suggest that the scarcity was partly a visibility problem.

What I'd want to know next is not simply which models a sample can call, but whether those calls improve an attack enough to justify the added complexity. Talos has shown that malware can assemble a committee of models. It has not shown that the committee is reliable, widely deployed or useful in real campaigns.

That tension defines the current moment: AI is already appearing as infrastructure inside malicious software, while the evidence for a mature AI-powered threat market remains thin.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X