Researchers from Cisco Talos have introduced an open-source framework called the Cognitive Artifact Intelligence Research Network (CAIRN) to classify and analyze malware that integrates artificial intelligence (AI). This announcement was made on Monday, as cybersecurity experts have observed an increase in the use of AI components in hacking tools. CAIRN aims to help identify and track malware by analyzing its characteristics and metadata.
Ryan Fetterman, a security researcher at Cisco Talos, explained that the framework is designed to detect AI integration fingerprints left by malware, which can assist in tracking and classifying these threats. The researchers have already used CAIRN to identify a malware tool named CLOSEDQUORUM, which operates autonomously by consulting multiple large language models (LLMs) for commands.
In July 2025, the Ukrainian cybersecurity unit CERT-UA reported a phishing campaign utilizing malware called “LAMEHUG,” which communicated with an LLM through an API. Fetterman noted that despite expectations of a surge in AI-enabled malware, he found only a limited number of documented examples during a retrospective review this summer, identifying about nine different malware families.
CAIRN flags characteristics of AI integration and assigns unique IDs to malware samples, allowing researchers to analyze trends and connections within the CAIRN library. After several months of using CAIRN, Fetterman discovered around 20 additional examples of AI-integrated malware, suggesting a more complex landscape than previously reported.
The CLOSEDQUORUM malware, identified by CAIRN, is designed for Windows and consults various AI services, including DeepSeek and Google Gemini, to determine its actions. It has been linked to cybercriminal forums related to credit card fraud and is intended to steal login credentials and cryptocurrency. However, researchers have not confirmed the developer of the malware or its use in actual attacks.
Matt Olney, senior director of threat intelligence at Cisco Talos, remarked on the shift in perception of AI from a productivity tool to a resource that attackers can leverage to enhance their operations and conduct more sophisticated campaigns.