Cisco Talos Uncovers AI-Driven Malware Using CAIRN Tool
Tech

Cisco Talos Uncovers AI-Driven Malware Using CAIRN Tool

TechNews Editorial
TechNews EditorialSep 22, 2026 · 2 min read
Share

Cisco Talos researchers have developed a new framework called Cognitive Artifact Intelligence Research Network, or CAIRN. The name comes from stone stacks hikers use to mark trails. This system tracks hacking tools that integrate artificial intelligence.

As hackers expand their use of AI services, researchers use CAIRN to identify infrastructure with fully autonomous command systems. The tool recently uncovered malware dubbed CLOSEDQUORUM. This malware plots moves within a target system by polling up to four large language models about what to do next.

CLOSEDQUORUM takes directives entirely from that AI hive mind. Ryan Fetterman led the development of CAIRN as a security researcher at Cisco Talos. He states that AI integration leaves digital fingerprints.

Fetterman explains that these fingerprints give defenders a signal to track samples and classify them. Researchers can observe emergent behaviors as these technologies become mainstream. In July 2025, Ukraine cybersecurity unit CERT-UA warned about a phishing campaign using LAMEHUG malware. That implant communicated with a Qwen model through a Hugging Face API to receive commands.

Fetterman initially expected a massive boom of AI-enabled malware. When he conducted a retrospective this summer, he only found about nine different named malware families. Some of those were academic proofs of concept.

CAIRN flags AI integration characteristics from metadata to classify malware samples with unique identifiers. The system groups them by traits to illustrate trends and connections. Fetterman has discovered about 20 additional examples of AI-integrated malware using the framework over the last few months.

He notes that the landscape is much more complex than previously reported. The CLOSEDQUORUM tool checks with DeepSeek, Qwen, Mistral, and Google Gemini to develop consensus on its next steps. The malware maintains enough redundancy to operate without human input even if one AI service drops offline.

Cisco Talos found links between the malware and cybercriminal forums discussing credit card fraud in 2025. The software steals login credentials and cryptocurrency. Researchers cannot confirm who developed the malware or if it has seen real-world use.

Matt Olney serves as senior director of threat intelligence at Cisco Talos. He notes that attackers now operationalize AI to run more campaigns and handle different computers through a backend intelligence box. Cisco Talos continues to monitor these developments.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Related Stories