Cisco Unveils CAIRN: New Weapon Against AI-Driven Malware Threats
September 22, 2026
Cisco Talos’ open-source framework, CAIRN, is designed to classify and analyze malware that uses AI components by identifying AI-integrated characteristics and tagging samples with unique IDs.
CAIRN aims to track AI-enabled malware by extracting fingerprints from metadata and other signals, helping researchers classify, compare, and map trends across samples.
Talos researchers have identified roughly 20 AI-integrated malware examples in recent months, indicating a more diverse and complex landscape than publicly reported, though many are still experimental.
CAIRN has helped uncover a fully autonomous AI-driven C2 malware named CLOSEDQUORUM, which polls multiple large language models to decide its actions without human input, creating a closed, redundant decision loop.
CLOSEDQUORUM operates as Windows malware that consults multiple AI services—DeepSeek, Qwen, Mistral, and Google Gemini—to reach consensus on next steps, and can function if one service is unavailable due to redundancy, with objectives including credential and cryptocurrency theft and potential ties to cybercriminal forums dating back to 2025.
While the development of CLOSEDQUORUM signals evolving threat capabilities, researchers cannot yet confirm the developers or real-world deployment.
The broader shift is toward viewing AI as an autonomous, operationalized force in cybercrime, enabling attackers to run more campaigns across more targets with minimal human involvement.
CAIRN, short for Cognitive Artifact Intelligence Research Network, is a new open-source framework from Cisco Talos designed to classify and analyze malware that uses AI components, by identifying AI-integrated characteristics and tagging samples with unique IDs.
The autonomous C2 model demonstrated by CLOSEDQUORUM creates a self-contained loop by querying multiple LLMs via various services to decide actions without human oversight.
The overarching goal of CAIRN is to give researchers a scalable method to extract signals from AI-enabled threats and build a map of how these capabilities connect across incidents.
Summary based on 1 source
Get a daily email with more Tech stories
Source

WIRED • Sep 22, 2026
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight