Cisco Talos unveils CAIRN tool that detects AI‑driven closedquorum malware
Cisco Talos researchers introduced CAIRN, a framework that flags AI‑integration traits in malware by analyzing metadata fingerprints and assigning unique IDs. Lead researcher Ryan Fetterman says the system looks for “fingerprints” left by AI services, helping the defensive community track emerging threats.
Key points
- Cisco Talos released CAIRN, a framework that tags AI‑integrated malware by analyzing metadata fingerprints.
- CAIRN uncovered CLOSEDQUORUM, Windows malware that polls DeepSeek, Qwen, Mistral and Google Gemini for autonomous commands.
- Researchers found roughly 20 more AI‑driven malware examples but cannot confirm developers or real‑world use.
Using CAIRN they identified a Windows tool called CLOSEDQUORUM that polls up to four large language models—DeepSeek, Qwen, Mistral and Google Gemini—to decide its next actions, operating without any human input. The malware is designed to steal login credentials and cryptocurrency and shows links to credit‑card‑fraud forums dating back to 2025. Researchers could not confirm who built it or whether it has been used in real‑world attacks.
The team also references earlier LAMEHUG malware that used Qwen2.5‑Coder‑32B‑Instruct via a Hugging Face API. Fetterman estimates CAIRN has now uncovered about 20 additional AI‑integrated malware samples, suggesting the threat landscape is more complex than previously reported.
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
More in Research
All →- Study finds generative AI has mixed effect on youth critical thinking and problem solving · 2 src
- Anthropic is setting up a biology lab where Claude guides robots in drug experiments · 1 src
- DeepInstructor agentic framework improves idea evaluation using experience graph from 58,607 peer reviews · 1 src
- Researchers identify context poisoning as extreme-value attention interference in long-context language models · 1 src
- AdaMem improves soft compression for retrieval-augmented generation · 1 src
Comments
via GitHub Discussions