Cisco Talos Released Open-Source AI Malware Tracker

Researchers launched the CAIRN framework to identify and monitor autonomous hacking tools using large language models.

Updated on Sept. 22, 2026 in Artificial Intelligence

Isometric editorial illustration of a structured server room and fiber-optic conduits, representing AI-driven cybersecurity infrastructure.
Cisco Talos released the CAIRN framework on September 21, 2026, to classify and track AI-integrated malware, including autonomous threats like CLOSEDQUORUM. AI Illustration. Upload story photo >

Live Poll

Do you believe the rise of AI-powered malware makes your personal digital information less secure?

Cisco Talos released the CAIRN framework on September 21, 2026, to classify and track malware integrated with artificial intelligence. The tool was developed to monitor the rising use of agentic AI components in malicious software, such as the autonomous CLOSEDQUORUM hacking tool.

Why it matters

The framework provides a necessary defense against evolving cyber threats that utilize LLMs to operate without human oversight. By automating the identification of AI-driven malware, security teams can better defend against advanced automated attacks targeting credentials and financial assets.

The CAIRN framework analyzes artifact metadata to classify malware based on AI traits. The CLOSEDQUORUM tool generates commands by polling four different LLMs—DeepSeek, Qwen, Mistral, and Google Gemini—to ensure redundancy and consensus.

The players

Cisco Talos

This is a prominent threat intelligence and security research division that provides detection and analysis for global cybersecurity threats.

CERT-UA

This is the Computer Emergency Response Team of Ukraine responsible for identifying and mitigating cyberattacks within the nation.

The details

The CLOSEDQUORUM malware operates entirely without human input, specifically targeting login credentials and cryptocurrency holdings. The framework also surfaced earlier activity, including a July 2025 phishing campaign detected by CERT-UA that used the LAMEHUG malware to communicate with an LLM via API.

Timeline

  1. July 2025: CERT-UA detected a phishing campaign utilizing LAMEHUG malware.

  2. 2025: CLOSEDQUORUM was first linked to illicit credit card fraud forums.

  3. September 21, 2026: Cisco Talos officially released the CAIRN framework.

The Tech Race

The emergence of CAIRN marks a shift in how cybersecurity firms counter the integration of public LLM APIs into malicious code. This development follows a pattern set by the Hugging Face API used by LAMEHUG for model communication, illustrating the risks of accessible AI interfaces.

The ability of malware to function autonomously means that standard credential and financial protections are increasingly at risk. Users should maintain heightened vigilance regarding phishing attempts and prioritize multi-factor authentication as automated tools become more prevalent.

The takeaway

As malicious actors increasingly offload complex decision-making to public LLMs, cybersecurity defenses must move toward automated, framework-based identification. Organizations should review their existing security posture to account for autonomous tools that do not require human interaction.

Further reading

Learn more about the latest developments in Artificial Intelligence security and research.

Live Poll

Do you believe the rise of AI-powered malware makes your personal digital information less secure?