Cisco Talos Reports Fully Autonomous AI-Directed Malware
Talos open-sourced CAIRN and reported the first malware with no human input that polls four LLMs for decisions; vendor research, real-world use unconfirmed.
Original event 2026-09-22
Cisco Talos has released an open-source framework called CAIRN and used it to identify a Windows malware dubbed CLOSEDQUORUM, which makes its decisions by polling four large language models — DeepSeek, Qwen, Mistral and Gemini — with no mechanism for human input.
The malware is designed to steal login credentials and cryptocurrency, and keeps polling the remaining models if one AI service is unavailable. Talos says CAIRN has surfaced about 20 additional AI-integrated malware samples, against roughly nine named families previously documented publicly, some of them research proofs of concept.
This is Talos's own research: the malware's authors and whether it has been used in real attacks remain unconfirmed. For defenders, CAIRN's fingerprinting approach for classifying AI-integrated malware is usable now.