A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.
Cognitive Artifact Intelligence Research Network (CAIRN), a malware identification tool developed by Cisco Talos researchers, has uncovered a new hacking tool called CLOSEDQUORUM. The AI-powered malware operates without any human intervention, polling up to four large language models (LLMs) such as DeepSeek, Qwen, Mistral, and Google Gemini to determine its course of action within a target system.
Ryan Fetterman, a security researcher at Cisco Talos, explains that the malware's reliance on AI integration leaves behind distinctive fingerprints, making it easier to track and classify these samples. Although CAIRN had identified only a few AI-integrated malware examples a year ago, Fetterman discovered around 20 additional instances after working with the tool for several months.
The CLOSEDQUORUM malware is designed to steal login credentials and cryptocurrency, and it has links to cybercriminal forums focused on credit card fraud dating back to 2025. However, the origin of the malware remains unknown, and it is unclear whether it has been utilized in actual attacks.
Written by urgent.news from Wired's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.