AIToday
WIRED AIPublished: Sep 22, 2026, 22:00 JST

Cisco Talos' CAIRN tool exposes AI-run malware CLOSEDQUORUM

Cisco Talos' CAIRN tool exposes AI-run malware CLOSEDQUORUM

3 Key Points

  1. What happened

    Cisco Talos shared CAIRN, an open-source framework for classifying AI-integrated malware. Using it, researcher Ryan Fetterman identified CLOSEDQUORUM, Windows malware that queries DeepSeek, Qwen, Mistral, and Google Gemini for its next steps.

  2. Why it matters

    CLOSEDQUORUM polls as many as four language models to build a consensus on its next move, with enough redundancy to run without any human input. That makes it hard to trace or disrupt, since no person is giving the orders, according to Cisco Talos.

  3. What to watch

    The researchers could not confirm who built the malware or whether it has been used in real attacks, so its actual spread is still unknown. Defenders will be watching whether other samples found through CAIRN show the same hive-mind design.

WHO IT HITSSecurity operations and threat-intelligence teams that write detection rules and track malware families will need to incorporate AI-artifact fingerprints like those CAIRN flags, since the body says AI-integrated samples are more diverse than public reports suggest.

Not sure about something? Ask the AI

Summaries like this, in your inbox every morning.

Context & Analysis

The CAIRN framework grew out of a gap between expectation and evidence. When Ukraine's CERT-UA warned in July 2025 about the LAMEHUG implant, which pulled commands from an LLM called Qwen2.5-Coder-32B-Instruct through a Hugging Face API, Ryan Fetterman at Cisco Talos expected a surge of AI-enabled malware. A retrospective this summer found the opposite: only about nine named families, some of them research proofs of concept. CAIRN is his answer — a way to flag the fingerprints AI integration leaves in metadata, tag samples with a unique ID, and group them so trends become visible. The CLOSEDQUORUM case shows why that gap between public reporting and reality may matter: the tool is designed to steal login credentials and cryptocurrency, and Cisco Talos saw links between it and cybercriminal forums about credit card fraud going back to 2025. What the researchers still cannot say is who built it or whether it has been used in real-world attacks, so its practical reach is unconfirmed. That leaves defenders with an early signal rather than a confirmed threat, and the value of CAIRN may hinge on whether other teams adopt it widely enough to surface more samples — something Fetterman and Matt Olney, Cisco Talos' senior director of threat intelligence, frame as attackers operationalizing AI rather than merely experimenting with it.

FAQ
How does CLOSEDQUORUM decide what to do next?
It polls up to four large language models — DeepSeek, Qwen, Mistral, and Google Gemini — and takes its directives from that consensus. Even if one service is unavailable, it keeps polling the others, so it needs no human input.
Why did Cisco Talos build CAIRN?
Researcher Ryan Fetterman expected a boom of AI-enabled malware after CERT-UA warned about LAMEHUG in July 2025, but a retrospective this summer found only about nine named malware families. He wanted a way to find more.
What has CAIRN found so far?
Fetterman says using CAIRN for the past few months turned up about 20 additional examples of AI-integrated malware. The framework tags samples with a unique ID from their metadata and groups them by traits.

Get AI news like this every morning

For example, today's edition would include:

  • Xiaomi open-sources MiMo-V2.6-Pro, tops open-weight AI indexSiliconANGLE AI · 1h ago
  • Hermes Testing Solutions debuts on OTC market on September 22DIGITIMES Asia · 1h ago
  • AI-exposed US jobs pay 46% more as entry roles vanishYahoo Finance AI · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Next articleMeta patches Muse exploit found by Patrick Wardle