Cisco Talos releases open-source CAIRN framework, identifies Windows malware CLOSEDQUORUM that queries multiple LLMs for autonomous command-and-control decisions
Cisco Talos publicly released CAIRN (Cognitive Artifact Intelligence Research Network), an open-source framework to detect, classify, and track AI-integration artifacts/fingerprints in malware. Using it, researchers identified and documented a specific new malware sample, CLOSEDQUORUM, which is Windows malware that polls up to four LLMs (DeepSeek, Qwen, Mistral, Google Gemini) to reach a 'consensus' on its next actions, operating with no human-in-the-loop control mechanism; it is designed to steal login credentials and cryptocurrency, with some links to credit-card-fraud forum activity since 2025, though actual real-world deployment/attribution is unconfirmed.
Entities: Cisco Talos, CAIRN, CLOSEDQUORUM, Ryan Fetterman, Matt Olney, DeepSeek
0 primary
What happened
Cisco Talos released CAIRN, an open-source framework for detecting AI-related fingerprints in malware, and used it to identify CLOSEDQUORUM, a Windows malware sample that queries up to four LLMs (DeepSeek, Qwen, Mistral, Google Gemini) to reach a "consensus" on its next actions with no human oversight. Talos says CAIRN also surfaced roughly 20 previously undocumented AI-integrated malware samples, versus around nine known families before this. The malware is designed to steal credentials and cryptocurrency and has loose links to credit-card-fraud forum activity since 2025, but there is no confirmed real-world deployment or victim.
Why it matters
If accurate, this gives defenders a concrete new detection tool and a documented example of malware attempting autonomous LLM-driven decision-making, which matters for security teams building AI-aware detection rules and for enterprises assessing exposure to a new malware category. The practical impact today is limited: this is one sample with unconfirmed deployment, not an active campaign, so the immediate action for most organisations is awareness and monitoring rather than emergency response.
What is noise
The framing of an "AI hive mind" with "no humans in sight" oversells a malware sample that queries commercial LLM APIs for decision support, which is a novel engineering choice but not evidence of emergent autonomous coordination. The extraction has no primary source links, meaning this is Wired's account of a Talos disclosure rather than the underlying technical report, so the ~20 additional samples and the "attackers operationalizing AI" trend claim cannot yet be independently checked against Talos's actual data.
Watch next
- 01Whether Cisco Talos publishes the actual technical report or repo (CAIRN on GitHub/GitHub-equivalent) with IOCs, code samples and detection rules for CLOSEDQUORUM, rather than just the Wired summary
- 02Any confirmed real-world detection of CLOSEDQUORUM in the wild (endpoint telemetry, incident reports, victim disclosures) versus it remaining a researcher-discovered sample with no confirmed deployment
- 03Whether other vendors (Microsoft, Google Mandiant, CrowdStrike) corroborate the ~20 additional AI-integrated malware families Talos claims to have found using CAIRN, and whether CAIRN sees independent adoption as a detection tool
Coverage
1 storyMore capability signals
Full feed →- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680
- WIRED investigation: Flock Safety's AI person-search tools let police run broad description-based surveillance, with weak guardrails against misuse3 Sept 202680
- Google DeepMind launches AlphaGenome Atlas, a free public database of predicted effects for 9 billion possible human genome variants8 Sept 202679