conv.

All stories
SecurityActive · 41h

Cisco Talos Finds Malware That Polls Multiple AI Chatbots for Its Next Move

A new open-source detection framework, CAIRN, surfaced CLOSEDQUORUM, a Windows hacking tool that consults up to four LLMs instead of a human operator.

What to know

  • Cisco Talos's new open-source CAIRN framework fingerprints AI-integrated malware by tracking metadata left behind by AI service calls.
  • It identified CLOSEDQUORUM, Windows malware with fully autonomous command-and-control that polls DeepSeek, Qwen, Mistral, and Google Gemini for a consensus decision on its next move.
  • Researcher Ryan Fetterman says CAIRN has already surfaced about 20 previously undocumented AI-integrated malware samples, beyond the roughly nine known families.
  • The finding builds on the 2025 LAMEHUG case, suggesting AI-directed malware is more common and varied than has been publicly reported.

“At the time I was like, 'Wow, this is amazing. There's gonna be this big boom of AI-enabled malware and the landscape is totally going to change,'”

Ryan Fetterman, Cisco Talos security researcher · Wired ↗ · Sep 21

Ryan Fetterman Cisco Talos security researcherCisco Talos Cybersecurity research unit (Cisco)CERT-UA Ukrainian cybersecurity response unit

Cisco Talos Finds Malware That Polls Multiple AI Chatbots for Its Next Move
wired.com

How it unfolded 1 development · click the chart to see its coverage articlesposts

Peak 13 pieces in one hour at Yesterday, 8 AM; 24 pieces over 42 hours (14 articles · 10 posts) Yesterday, 5 AM — 2 pieces · 2 articles — Mastodon 1, Newswires 1Yesterday, 6 AM — quietYesterday, 7 AM — 1 piece · 1 article — Newswires 1Yesterday, 8 AM — 13 pieces · 9 articles · 4 posts — Newswires 9, Bluesky 2, Mastodon 1, +1 moreYesterday, 9 AM — 1 piece · 1 post — Mastodon 1Yesterday, 10 AM — quietYesterday, 11 AM — quietYesterday, 12 PM — quietYesterday, 1 PM — 3 pieces · 1 article · 2 posts — Mastodon 2, Google News 1Yesterday, 2 PM — quietYesterday, 3 PM — quietYesterday, 4 PM — quietYesterday, 5 PM — 1 piece · 1 article — Newswires 1Yesterday, 6 PM — quietYesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — quietYesterday, 11 PM — quietToday, 12 AM — 1 piece · 1 post — Mastodon 1Today, 1 AM — quietToday, 2 AM — quietToday, 3 AM — quietToday, 4 AM — quietToday, 5 AM — quietToday, 6 AM — quietToday, 7 AM — 1 piece · 1 post — Hacker News 1Today, 8 AM — quietToday, 9 AM — quietToday, 10 AM — 1 piece · 1 post — Mastodon 1Today, 11 AM — quietToday, 12 PM — quietToday, 1 PM — quietToday, 2 PM — quietToday, 3 PM — quietToday, 4 PM — quietToday, 5 PM — quietToday, 6 PM — quietToday, 7 PM — quietToday, 8 PM — quietToday, 9 PM — quietToday, 10 PM — quiet 1
8 AM4 PMtoday8 AM4 PMnow · 11:21 PM ET
  1. 1

    Wired publishes the CAIRN/CLOSEDQUORUM findings

    Wired reported the details of CAIRN and CLOSEDQUORUM, with the story circulating via Techmeme and social reposts.

    “The core idea is that AI integration has these vestiges, like fingerprints, that are left behind…”
    — Ryan Fetterman, Cisco Talos security researcher · source
    • TalosSecurity@mstdn.social

      Cisco Talos is proud to introduce CAIRN, a new metadata-first research toolkit designed to scale the hunting and classification of AI-integrated malware without defenders needing to download binaries: https:// blog.talosintelligence.com/int roducing-cairn-frontier-tracking-for-ai-integrated-malware

      TalosSecurity@mstdn.socialMastodon1d agoview on Mastodon ↗
    2 more of the top 3 · 5 posts in this stretch
    • Cisco Talos spotted Windows malware, CLOSEDQUORUM, taking orders from an LLM hive mind without human input. It polls DeepSeek, Qwen, Mistral, and Gemini to decide next steps. Researchers flagged it via CAIRN, a new open-source system cataloging AI fingerprints in code.

      @smcgrath.phdBluesky1d agoview on Bluesky ↗
    • AAKL@infosec.exchange

      New product announcement. Cisco: Introducing CAIRN: Frontier tracking for AI-integrated malware https:// blog.talosintelligence.com/int roducing-cairn-frontier-tracking-for-ai-integrated-malware/ @ TalosSecurity # Cisco # infosec # malware @ ifin

      AAKL@infosec.exchangeMastodon1d agoview on Mastodon ↗
    all of them →
  2. background

    Cisco Talos releases CAIRN and identifies CLOSEDQUORUM malware — Cisco Talos publicly shared the open-source CAIRN framework and disclosed that it had used it to find CLOSEDQUORUM, Windows malware with fully autonomous command-and-control that polls up to four LLMs to decide its next steps.

  3. background

    CAIRN library surfaces about 20 more AI-integrated malware samples — After months of building and running the CAIRN framework, Fetterman says it turned up roughly 20 additional examples of AI-integrated malware beyond what had been publicly documented.

  4. background

    Fetterman's retrospective finds only a handful of AI-malware cases — Doing a retrospective on AI-integrated malware, Cisco Talos researcher Ryan Fetterman was surprised he could document only about nine named malware families, some merely proofs of concept, prompting him to dig further.

  5. background

    CERT-UA warns of LAMEHUG malware taking orders from an LLM — Ukraine's cybersecurity response unit flagged a phishing campaign using malware called LAMEHUG, which communicated with the LLM Qwen2.5-Coder-32B-Instruct via a Hugging Face API to receive commands.

Also covered reported alongside — the timeline has no entry for these yet

  1. first by Unite.AI, 1d ago · also Cisco Talos Blog, Wired

    2 more headlines
  2. first by BleepingComputer, 1d ago · also The Register

    1 more headline
  3. first by Mastodon, 1d ago · also Wired

and 4 smaller pieces

What people are saying 1 voices from 1 site · best of 5 · verbatim