Cisco Talos open-sources CAIRN and reports CLOSEDQUORUM, the first known malware that lets a committee of LLMs choose its next move
On Sept 22, 2026 Cisco Talos released CAIRN, an open-source toolkit that finds AI-integrated malware by scanning metadata (prompt templates, API endpoints, jailbreak strings) without running the binaries. With it Talos found CLOSEDQUORUM, a Windows implant that asks up to four LLMs (DeepSeek, Qwen, Mistral, Gemini) what to do next and executes the plurality vote. Talos calls it the first reported autonomous AI command-and-control implant, though no in-the-wild deployment has been confirmed.
Key facts
- CAIRN: open-source Talos research toolkit for hunting, classifying and tracking AI-integrated malware by its AI metadata and behavioral fingerprints
- CLOSEDQUORUM: Go-based Windows implant (~16.4MB per secondary reports); queries DeepSeek, Qwen, Mistral and Google Gemini in turn; each model votes among constrained actions (steal credentials, inject code, establish persistence, move laterally); the plurality wins
- Quorum design keeps working if one provider fails or refuses on safety grounds
- Targets LSASS dumps, browser passwords and crypto wallets; exfiltrates via Discord webhooks
- Caveats: the public build has dummy API keys and non-functional webhooks (an inert template); Talos did not observe end-to-end execution and has not confirmed real-world use
- Talos (Ryan Fetterman): 'After deployment, tactical choices are delegated to a model-driven decision loop.'
What happened
Cisco Talos published CAIRN, an open-source framework that looks for traces of AI use inside malware (prompt templates, model API endpoints, jailbreak terms) using static metadata rather than execution. One of its first finds was CLOSEDQUORUM, a Windows implant that, after deployment, hands its tactical choices to a panel of commercial and open LLMs and acts on their majority vote, with no human operator issuing commands.
Why it matters
Earlier AI-assisted malware used models as an optional helper for speed and scale. CLOSEDQUORUM is the first reported design in which models run the command-and-control loop themselves, and its voting scheme is built to route around individual providers' safety refusals. The sample appears to be an unconfigured template, so its real-world impact is unknown.
Changelog
- 2026-09-29: created (sweep 2026-09-29)
Related events
- Anthropic threat intelligence report: AI-orchestrated cyberattacks and distillation by Chinese labs ★★★
- Google threat intelligence: dark-web markets sell access to OpenAI, Anthropic and Google models at up to 97% off; LLM-jacking surges ★★
Sources (3)
- officialCisco Talos: Introducing CAIRN, frontier tracking for AI-integrated malware
- officialCisco Talos: The Closed Quorum, inside the first reported autonomous AI C2 implant
- pressWired: A tool for tracking AI-integrated malware uncovered an autonomous command system
id: 2026-09-22-cisco-talos-cairn-closedquorum · updated 2026-09-29 · open in the interactive timeline