Cisco Talos Unveils CAIRN Framework to Track AI-Integrated Malware with Autonomous Command Systems

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cybersecurity researchers at Cisco Talos have introduced an open-source framework called the Cognitive Artifact Intelligence Research Network (CAIRN) to help classify and analyze AI-integrated malware. This development comes as cybercriminals increasingly incorporate agentic AI components into their hacking tools. The framework aims to track the evolving landscape of malware, which is becoming more sophisticated with the integration of artificial intelligence.

CAIRN has already been used to identify a hacking tool known as CLOSEDQUORUM, which operates with a fully autonomous command-and-control infrastructure. This malware utilizes up to four large language models (LLMs) to determine its actions within a target system, effectively creating a hive mind for decision-making. According to Ryan Fetterman, a security researcher at Cisco Talos, the framework captures unique characteristics of AI integration, allowing for better tracking and classification of malware samples.

In a notable case, the Ukrainian cybersecurity response unit CERT-UA warned in July 2025 about a phishing campaign utilizing malware named “LAMEHUG,” which communicated with an LLM through a Hugging Face API. Fetterman expressed surprise at the limited number of documented AI-integrated malware examples, initially expecting a significant increase in such threats. However, his research revealed only a handful of named malware families, prompting further investigation.

CAIRN is designed to flag AI-integration characteristics from metadata, assigning unique IDs to malware samples and analyzing them within the context of its library. Fetterman noted that his recent work with CAIRN has uncovered around 20 additional examples of AI-integrated malware, indicating a more complex and diverse landscape than previously reported.

The CLOSEDQUORUM malware, identified by CAIRN, is a Windows-based threat that consults multiple AI services, including DeepSeek, Qwen, Mistral, and Google Gemini, to determine its next steps. This redundancy ensures that the system remains operational even if one AI service is unavailable. While links to cybercriminal forums related to credit card fraud have been observed, the researchers could not confirm the malware’s developer or its use in real-world attacks.

Matt Olney, senior director of threat intelligence at Cisco Talos, remarked on the shift in perception of AI from a productivity tool to an operational asset for attackers, enabling them to conduct more extensive and varied campaigns.

For further details, see the full report by Wired.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CISA Unveils Plan to Enhance Quality of Common Vulnerabilities and Exposures Program Amid Rising CVE Submissions

The Cybersecurity and Infrastructure Security Agency (CISA) has released a white paper outlining its strategy to enhance the Common Vulnerabilities and Exposures (CVE) program,...

Red Hat releases important kernel security update for RHEL 8.6 Advanced and Extended Support

Red Hat has announced a significant kernel security update for its Red Hat Enterprise Linux (RHEL) 8.6 Advanced Mission Critical Update Support and RHEL...

Syria seeks to transform Russian military bases into training centers

Syria is seeking to transform Russian military bases into training centers for its own armed forces, as part of a broader strategy to eliminate...

Armenian National Sentenced to Two Years for Role in Ryuk Ransomware Attacks

An Armenian national has been sentenced to two years in U.S. federal prison after pleading guilty to charges related to multiple ransomware attacks. Karen...