344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps175
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support133
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Cisco Talos shared an open-source system called CAIRN to spot malware that uses AI chatbots and it found a sample that can choose actions on its own.
In short: Cisco Talos has released an open-source tool called CAIRN to identify malware that uses AI chatbots, and it helped researchers find a strange, highly automated malware sample.
Cisco Talos, the security research team at Cisco, shared a new framework called the Cognitive Artifact Intelligence Research Network, or CAIRN. It is meant to help researchers recognize and label “AI-integrated malware,” which is malicious software that calls out to AI chatbots for help.
Security teams usually track malware using digital fingerprints, which are small clues that help link one sample to another. CAIRN looks for similar clues tied to AI use, like details in code and other metadata (basic information about a file, like labels on a package). It then tags samples with an ID and groups them so researchers can spot patterns.
Using CAIRN, the team identified a Windows malware tool they named CLOSEDQUORUM. Cisco Talos says this malware asked up to four large language models, which are text-generating AI systems, what to do next. The models mentioned were DeepSeek, Qwen, Mistral, and Google Gemini. Talos says the malware was built to keep going even if one AI service was unavailable, and it had no way for a human operator to step in.
Cisco Talos also said CAIRN helped them find about 20 additional examples of malware that appears to use AI, beyond the small number that had been publicly documented.
If more malware starts using AI systems as a built-in “decision helper” (like a thief calling several advisers before taking the next step), defenders will need new ways to spot it early. Tools like CAIRN are meant to help researchers connect the dots faster, even when the malware’s behavior changes from one attack to the next.
Source: Wired