A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight

Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.

A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight

A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight

Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.
A New Tool Found Malware Thats Guided by an AI Hive Mind—No Humans in Sight
Photo-Illustration: Jobanny Cabrera; Getty Images

For years, cybersecurity practitioners have tracked different types of malware and detected potential infections using digital fingerprints to identify different hacking tools and follow their use over time. As attackers are increasingly incorporating agentic AI components into their hacking tools, researchers from Cisco Talos shared an open-source framework on Monday that they hope will be used widely to classify and analyze AI-integrated malware. They also have proof that it’s already working.

They’re calling the framework Cognitive Artifact Intelligence Research Network, or CAIRN, named after the stacks of stones that hikers set up on trails to mark the path or emphasize something about a certain spot. As malware authors expand their use of AI services, Cisco Talos researchers have used CAIRN to identify a hacking tool with fully autonomous command-and-control infrastructure. Dubbed CLOSEDQUORUM, the malware plotted its moves within a target system by polling up to four large language models (LLMs) about what it should do and taking its directives from that hive mind.

“The core idea is that AI integration has these vestiges, like fingerprints, that are left behind,” says Ryan Fetterman, a security researcher at Cisco Talos who led development of CAIRN. “That gives us a signal that we can use to track these samples, classify them, and look at what’s happening. What are attackers trying? What kind of emergent behaviors are we seeing? That’s a valuable resource to the defensive community as these things become more mainstream.”

In July 2025, the Ukrainian cybersecurity response unit CERT-UA warned about a phishing campaign it had detected using malware known as “LAMEHUG.” The implant communicated with an LLM called Qwen2.5-Coder-32B-Instruct through a Hugging Face API to get commands. “At the time I was like, ‘Wow, this is amazing. There’s gonna be this big boom of AI-enabled malware and the landscape is totally going to change,’” Fetterman says.

A year later, though, when he went to do a retrospective this summer of malware integrating AI, Fetterman was shocked that he could still only find a few documented examples. “There really wasn’t a lot there. I think I came up with maybe nine different named malware families,” and some of those were proofs of concept created for research, he says. “It just wasn’t what I was expecting, and I think I also had a hard time believing that that was the reality of where we were. So I wanted to start digging into that.”

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.