Cybersecurity researchers at Cisco Talos have introduced an open-source framework called the Cognitive Artifact Intelligence Research Network (CAIRN) to help classify and analyze AI-integrated malware. This development comes as cybercriminals increasingly incorporate agentic AI components into their hacking tools. The framework aims to track the evolving landscape of malware, which is becoming more sophisticated with the integration of artificial intelligence.
CAIRN has already been used to identify a hacking tool known as CLOSEDQUORUM, which operates with a fully autonomous command-and-control infrastructure. This malware utilizes up to four large language models (LLMs) to determine its actions within a target system, effectively creating a hive mind for decision-making. According to Ryan Fetterman, a security researcher at Cisco Talos, the framework captures unique characteristics of AI integration, allowing for better tracking and classification of malware samples.
In a notable case, the Ukrainian cybersecurity response unit CERT-UA warned in July 2025 about a phishing campaign utilizing malware named “LAMEHUG,” which communicated with an LLM through a Hugging Face API. Fetterman expressed surprise at the limited number of documented AI-integrated malware examples, initially expecting a significant increase in such threats. However, his research revealed only a handful of named malware families, prompting further investigation.
CAIRN is designed to flag AI-integration characteristics from metadata, assigning unique IDs to malware samples and analyzing them within the context of its library. Fetterman noted that his recent work with CAIRN has uncovered around 20 additional examples of AI-integrated malware, indicating a more complex and diverse landscape than previously reported.
The CLOSEDQUORUM malware, identified by CAIRN, is a Windows-based threat that consults multiple AI services, including DeepSeek, Qwen, Mistral, and Google Gemini, to determine its next steps. This redundancy ensures that the system remains operational even if one AI service is unavailable. While links to cybercriminal forums related to credit card fraud have been observed, the researchers could not confirm the malware’s developer or its use in real-world attacks.
Matt Olney, senior director of threat intelligence at Cisco Talos, remarked on the shift in perception of AI from a productivity tool to an operational asset for attackers, enabling them to conduct more extensive and varied campaigns.
For further details, see the full report by Wired.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


