Skip to main content
Live
Main content

Cisco Talos releases CAIRN, uncovers malware run by a four-LLM hive mind

New open-source framework flagged CLOSEDQUORUM, which polls DeepSeek, Qwen, Mistral, and Gemini for its next move with no human in the loop.

Jaeden Schafer
Editor in Chief · · 5 min read
Cisco Talos releases CAIRN, uncovers malware run by a four-LLM hive mind

Cisco Talos released an open-source framework on September 22, 2026 for classifying AI-integrated malware, and the first thing it turned up was a Windows implant that runs its command-and-control loop by polling four large language models and acting on the consensus. The framework, called CAIRN — Cognitive Artifact Intelligence Research Network — fingerprints the metadata traces that AI-integration leaves behind in malware samples, then groups them to expose trends. The malware Talos identified with it, dubbed CLOSEDQUORUM, has no human operator in the loop at all.

CLOSEDQUORUM queries DeepSeek, Qwen, Mistral, and Google Gemini in sequence to decide its next move on an infected machine. If one service is unreachable, it falls through to the others, meaning the system is fully closed and self-directing. Talos tied the sample to cybercriminal forums discussing credit card fraud going back to 2025, and its payload is built to steal login credentials and cryptocurrency, though researchers could not confirm who wrote it or whether it has been used in a live campaign.

The premise behind CAIRN is that calling out to an LLM is not free — it leaves observable artifacts in code, network traffic, and behavior. Ryan Fetterman, the Cisco Talos security researcher who led CAIRN's development, describes those artifacts as fingerprints defenders can catalog the same way they catalog any other malware family trait.

Key facts

  • 01Cisco Talos open-sourced CAIRN on September 22, 2026, a framework for fingerprinting AI-integrated malware from its metadata traces.
  • 02CAIRN surfaced CLOSEDQUORUM, Windows malware that polls up to four LLMs — DeepSeek, Qwen, Mistral, and Google Gemini — for its next command.
  • 03Researcher Ryan Fetterman found only 9 named AI-integrated malware families in a mid-2026 retrospective, then uncovered roughly 20 more using CAIRN.
  • 04CLOSEDQUORUM has no human command channel — if one model is unavailable, it queries the others and acts on the consensus.
  • 05Talos linked CLOSEDQUORUM to 2025 credit-card fraud forums; the malware targets login credentials and cryptocurrency wallets.

The project started as a retrospective. In July 2025, Ukraine's CERT-UA published a warning about a phishing campaign using malware known as LAMEHUG, which pulled its commands from Qwen2.5-Coder-32B-Instruct through a Hugging Face API. Fetterman expected LAMEHUG to be the front edge of a wave. When he went looking a year later in summer 2026, he could document only about nine named AI-integrated malware families, several of them research proofs of concept rather than deployed threats.

That gap between the expected boom and the visible reality is what motivated CAIRN. Rather than count only what had been publicly named, Fetterman built a system to hunt for the fingerprints directly. Using CAIRN over the past few months, he has surfaced roughly 20 additional examples of AI-integrated malware beyond the nine documented families — a threefold expansion of the known set.

CLOSEDQUORUM is the most structurally striking of those finds. Most AI-enabled malware to date has used a single model as a helper: generating obfuscated code, drafting phishing lures, or answering a specific question. CLOSEDQUORUM treats the models as a decision-making committee, which both increases resilience against any one provider blocking the traffic and eliminates the operator-side infrastructure that defenders have historically used to disrupt botnets.

So while I do think this is still largely experimental for attackers, the landscape is a lot more complex and diverse than has been publicly reported.
Ryan Fetterman, Security researcher at Cisco Talos

The four-model architecture is also a hedge against provider-side safety measures. If DeepSeek or Gemini refuses a prompt or rate-limits a suspicious pattern, the malware still gets a usable answer from Qwen or Mistral. For defenders, that means shutting down a single API key or provider relationship no longer takes the operation offline — a meaningful shift in the takedown playbook.

Matt Olney, senior director of threat intelligence at Cisco Talos, frames the broader trend as attackers moving past AI-as-productivity into AI-as-operator.

Related · from this week
Anthropic blocks scientists from using Claude for bioweapon research
Jaeden Schafer · 5 min read →

Talos is releasing CAIRN as open source so other researchers can extend the library and contribute samples. The company has not published detection signatures for CLOSEDQUORUM specifically, and the malware's real-world footprint remains unclear — Fetterman is candid that AI-integrated malware is still largely experimental among attackers, and that the counted samples number in the low dozens rather than the thousands.

The unknowns cut both ways. Talos could not verify authorship of CLOSEDQUORUM or whether victims have been hit, and treating a handful of samples as a trendline is exactly the kind of extrapolation that produced the overheated 2025 forecasts CAIRN was built to correct. A framework that measures fingerprints is only as useful as the sample pool it draws from, and that pool is still small.

The interesting shift for the AI security market is not the malware count — it is that defenders now have a categorization primitive built specifically for LLM-integrated tooling, released before the wave rather than after it. If CAIRN gets adoption across other threat-intel teams, the industry will finally have shared vocabulary for AI-enabled samples, which is the precondition for shared detections. The bigger question CLOSEDQUORUM raises is commercial: whether frontier model providers treat autonomous malware polling their APIs as an abuse problem worth engineering against, or as traffic they cannot practically distinguish from a developer building an agent.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Anthropic blocks scientists from using Claude for bioweapon research

The company detailed five cases where users circumvented controls to probe biological threats, including avian influenza work from a banned region.

Jaeden Schafer5 min read
Anthropic logo
Security

Anthropic says China labs ran 200M-exchange distillation attack on Claude

Alibaba, Moonshot AI, and DeepSeek tied to five campaigns harvesting Claude's reasoning traces, with one Moonshot request routed from the Chinese military.

Jaeden Schafer5 min read
UK AISI: open-weight models now trail closed AI on cyber by 4-7 months
Security

UK AISI: open-weight models now trail closed AI on cyber by 4-7 months

GLM-5.2 and DeepSeek V4-Pro closed the cyber capability gap from 6-10 months to 4-7 months. Kimi K3 is next in line.

Jaeden Schafer5 min read