AI-Powered Malware: Cybersecurity Experts Uncover New Threats
Cybersecurity experts have been tracking various types of malware for years, identifying potential infections through digital fingerprints. However, as attackers increasingly incorporate AI components into their tools, researchers from Cisco Talos created an open-source framework called Cognitive Artifact Intelligence Research Network (CAIRN) to classify and analyze AI-integrated malware.
CAIRN was designed to flag AI-integration characteristics and attributes from metadata, classifying and tagging malware samples with a unique ID. The system then analyzes each artifact in the context of everything in the CAIRN library, grouping them by various traits to illustrate potential trends and connections.
The researchers used CAIRN to identify a hacking tool called CLOSEDQUORUM, which plotted its moves within a target system by polling up to four large language models about what it should do. Even if one AI service was unavailable, the malware still polled the others, creating enough redundancy that the system had no mechanism for human input.
Closed QUORUM is Windows malware designed to steal login credentials and cryptocurrency, with links to cybercriminal forums about credit card fraud dating back to 2025. The researchers could not confirm who developed the malware or whether it has been used in real-world attacks.