RESEARCH · RESEARCH · #777
Cisco Talos releases CAIRN framework and uses it to identify CLOSEDQUORUM AI-driven malware
Cisco Talos published an open-source framework called CAIRN to tag and classify AI-integrated malware artifacts; using it, researchers identified a Windows malware family dubbed CLOSEDQUORUM that polls multiple LLMs (DeepSeek, Qwen, Mistral, Google Gemini) for autonomous command-and-control decisions. The team also found about 20 additional AI-integrated samples and noted earlier reports such as CERT-UA's July 2025 warning about LAMEHUG communicating with Qwen2.5-Coder-32B-Instruct via the Hugging Face API, while remaining unable to confirm CLOSEDQUORUM's real-world use or authorship.
KEY POINTS
- Cisco Talos published an open-source framework called CAIRN to tag and classify AI-integrated malware artifacts; using it, researchers identified a Windows malware family dubbed CLOSEDQUORUM that polls multiple LLMs (DeepSeek, Qwen, Mistral, Google Gemini) for autonomous command-and-control decisions.
- The team also found about 20 additional AI-integrated samples and noted earlier reports such as CERT-UA's July 2025 warning about LAMEHUG communicating with Qwen2.5-Coder-32B-Instruct via the Hugging Face API, while remaining unable to confirm CLOSEDQUORUM's real-world use or authorship.
- This shows attackers are beginning to operationalize multi-LLM, autonomous command-and-control and provides defenders a new open-source signal (CAIRN) to detect and track AI-integrated malware.
WHY IT MATTERS
This shows attackers are beginning to operationalize multi-LLM, autonomous command-and-control and provides defenders a new open-source signal (CAIRN) to detect and track AI-integrated malware.