Skip to content
CAIRN Unveils Tracking for AI-Integrated Malware

CAIRN Unveils Tracking for AI-Integrated Malware

First seen 22 Sep 2026, 11:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 12:54 UTC
  • CAIRN is a new framework for tracking AI-integrated malware developed by Cisco Talos.
  • The tool has already identified a malware variant called CLOSEDQUORUM, which uses AI for command-and-control.
  • CAIRN operates on a metadata-first approach, enabling rapid identification without executing binaries.

Cisco Talos has launched CAIRN, a new framework for identifying and classifying AI-integrated malware. This tool utilizes cognitive artifacts left by malware authors, such as API keys and prompt templates, to track and analyze malware behavior without needing to execute binaries. CAIRN has already identified a malware variant called CLOSEDQUORUM, which uses multiple large language models for autonomous command-and-control. The framework aims to enhance the cybersecurity community's ability to respond to the evolving threat landscape posed by AI-integrated malware. Researchers have discovered 20 new examples of such malware using CAIRN, indicating a growing trend in AI-enabled cyber threats. The tool operates on a metadata-first architecture, allowing for rapid identification and classification of threats. This development comes amid increasing concerns about the integration of AI in cyberattacks, as seen in previous incidents like the LAMEHUG malware campaign.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-07-01
LAMEHUG phishing campaign reported
CERT-UA warned about a phishing campaign utilizing LAMEHUG malware, which communicated with an LLM for commands.
Wired
2026-09-22
CAIRN framework launched
Cisco Talos introduced CAIRN to track and classify AI-integrated malware, enhancing cybersecurity defenses.
Blog.Talosintelligence
2026-09-22
CLOSEDQUORUM identified
Using CAIRN, researchers discovered the CLOSEDQUORUM malware, which autonomously polls LLMs for commands.
Wired

More articles in this cluster (3)

Following this threat?

Track Closedquorum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed