Cisco Talos Finds Malware That Polls Multiple AI Chatbots for Its Next Move
A new open-source detection framework, CAIRN, surfaced CLOSEDQUORUM, a Windows hacking tool that consults up to four LLMs instead of a human operator.
What to know
- Cisco Talos's new open-source CAIRN framework fingerprints AI-integrated malware by tracking metadata left behind by AI service calls.
- It identified CLOSEDQUORUM, Windows malware with fully autonomous command-and-control that polls DeepSeek, Qwen, Mistral, and Google Gemini for a consensus decision on its next move.
- Researcher Ryan Fetterman says CAIRN has already surfaced about 20 previously undocumented AI-integrated malware samples, beyond the roughly nine known families.
- The finding builds on the 2025 LAMEHUG case, suggesting AI-directed malware is more common and varied than has been publicly reported.
“At the time I was like, 'Wow, this is amazing. There's gonna be this big boom of AI-enabled malware and the landscape is totally going to change,'”
Ryan Fetterman, Cisco Talos security researcher · Wired ↗ · Sep 21
Ryan Fetterman Cisco Talos security researcherCisco Talos Cybersecurity research unit (Cisco)CERT-UA Ukrainian cybersecurity response unit
How it unfolded 1 development · click the chart to see its coverage articlesposts
-
1
Wired publishes the CAIRN/CLOSEDQUORUM findings
Wired reported the details of CAIRN and CLOSEDQUORUM, with the story circulating via Techmeme and social reposts.
“The core idea is that AI integration has these vestiges, like fingerprints, that are left behind…”
— Ryan Fetterman, Cisco Talos security researcher · source -
T
Cisco Talos is proud to introduce CAIRN, a new metadata-first research toolkit designed to scale the hunting and classification of AI-integrated malware without defenders needing to download binaries: https:// blog.talosintelligence.com/int roducing-cairn-frontier-tracking-for-ai-integrated-malware
2 more of the top 3 · 5 posts in this stretch
-
Cisco Talos spotted Windows malware, CLOSEDQUORUM, taking orders from an LLM hive mind without human input. It polls DeepSeek, Qwen, Mistral, and Gemini to decide next steps. Researchers flagged it via CAIRN, a new open-source system cataloging AI fingerprints in code.
-
A
New product announcement. Cisco: Introducing CAIRN: Frontier tracking for AI-integrated malware https:// blog.talosintelligence.com/int roducing-cairn-frontier-tracking-for-ai-integrated-malware/ @ TalosSecurity # Cisco # infosec # malware @ ifin
-
-
background
Cisco Talos releases CAIRN and identifies CLOSEDQUORUM malware — Cisco Talos publicly shared the open-source CAIRN framework and disclosed that it had used it to find CLOSEDQUORUM, Windows malware with fully autonomous command-and-control that polls up to four LLMs to decide its next steps.
-
background
CAIRN library surfaces about 20 more AI-integrated malware samples — After months of building and running the CAIRN framework, Fetterman says it turned up roughly 20 additional examples of AI-integrated malware beyond what had been publicly documented.
-
background
Fetterman's retrospective finds only a handful of AI-malware cases — Doing a retrospective on AI-integrated malware, Cisco Talos researcher Ryan Fetterman was surprised he could document only about nine named malware families, some merely proofs of concept, prompting him to dig further.
-
background
CERT-UA warns of LAMEHUG malware taking orders from an LLM — Ukraine's cybersecurity response unit flagged a phishing campaign using malware called LAMEHUG, which communicated with the LLM Qwen2.5-Coder-32B-Instruct via a Hugging Face API to receive commands.
Also covered reported alongside — the timeline has no entry for these yet
-
first by Unite.AI, 1d ago · also Cisco Talos Blog, Wired
2 more headlines
-
first by BleepingComputer, 1d ago · also The Register
1 more headline
-
first by Mastodon, 1d ago · also Wired
and 4 smaller pieces
What people are saying 1 voices from 1 site · best of 5 · verbatim
- Yesterday
-
NEW: Cisco Talos researchers built a tool to ID malware that integrates AI tools. It quickly found a command-and-control server for malware that is entirely directly by AI to plan its attack methods. @lhn.bsky.social has the scoop: