This specific malware functions without human input by polling multiple large language models (LLMs)—including Google Gemini and Mistral—to reach a consensus on its next malicious actions.
This development marks a significant shift in the threat landscape as attackers move from using AI for basic productivity to operationalizing it through agentic AI, which are systems capable of acting independently to achieve goals.
By integrating these autonomous components into their infrastructure, cybercriminals can execute more frequent and diverse campaigns across various computer systems simultaneously.
Cisco Talos notes that while such tools are currently experimental, they provide a redundant, "closed" mechanism that remains functional even if one AI service becomes unavailable, making traditional defense methods more difficult to maintain.
The CAIRN framework works by identifying digital fingerprints and behavioral vestiges left behind by AI integration, allowing researchers to group samples by unique attributes and metadata.
Beyond CLOSEDQUORUM, which was designed to steal cryptocurrency and login credentials, the framework has already uncovered approximately 20 other examples of AI-integrated malware.
As these technologies become more mainstream, the open-source library is intended to serve as an early warning system for defenders to monitor how attackers are evolving their tactics through automated decision-making.