Skip to main content
The Quantum Dispatch
Back to Home
Cover illustration for Cisco Talos CAIRN: Open-Source Tracking for AI Malware

Cisco Talos CAIRN: Open-Source Tracking for AI Malware

Cisco Talos open-sourced CAIRN, which finds AI-integrated malware from VirusTotal metadata alone, using three evidence tiers and never running a sample.

Kai Aegis
Kai Aegis★Sep 22, 2026★5 min read

A Field Guide for a New Kind of Threat

Cisco Talos released CAIRN on September 22, an open-source framework for hunting, classifying and tracking malware that has large language models built into it. The name stands for Cognitive Artifact Intelligence Research Network, and like the stone trail markers it is named after, it helps defenders see where something has passed and which way it is heading. It is available now on GitHub.

  • What it tracks: AI-integrated malware, identified through the traces that AI integration leaves behind
  • How it works: metadata-first analysis of VirusTotal data, with no need to download or run samples
  • How it classifies: three tiers of evidence, from simple AI artifacts up to named malware families
  • Track record: it has been monitoring the landscape since July 2025, back to LAMEHUG, the earliest known AI-integrated sample, per Help Net Security

What Are Cognitive Artifacts?

When an attacker wires an LLM into their tooling, they leave fingerprints. Talos calls these cognitive artifacts: embedded prompt templates, AI provider API endpoints, API key prefixes, orchestration logic that manages the model, jailbreak terms, and even text written specifically to confuse AI-powered analysis sandboxes. Traditional signatures look for known bad code. CAIRN looks for the scaffolding that any AI-assisted malware needs, which makes it useful against families nobody has named yet.

How Does CAIRN Classify AI Malware?

Talos organizes findings into three tiers, according to the Talos blog post by researcher Ryan Fetterman:

  • Tier 1: primitive AI artifacts, such as a model provider's endpoint or tool-call syntax, confirming that AI-related strings are present
  • Tier 2: behavioral context, such as evasion techniques or command-and-control methods that show the AI is part of how the malware operates
  • Tier 3: operational attribution, reserved for confirmed, named malware families

Under the hood it combines acquisition filters, relationship-based pivoting between samples, YARA-based classification and semantic discovery using embedding models, then maps the results as a relationship graph. Help Net Security describes the same toolkit as four hunting strategies: surface expansion, pivoting, corpus analysis and hunt sessions that combine them.

What Has CAIRN Found So Far?

Its first published finding is an implant Talos calls CLOSEDQUORUM, described as the first publicly documented Windows implant that hands command-and-control decisions to a panel of commercial LLMs. According to Help Net Security, it is a 16.4MB Go binary that asks four models in priority order to vote on its next move, with the majority winning. The encouraging detail: the sample Talos examined contained placeholder API keys and dummy webhook addresses, so it appears to be a work in progress rather than a live campaign. Finding it at that stage is exactly the point of early-warning tooling.

How Should Defenders Use CAIRN?

Talos is candid about its limits, which is a good sign. Expect false-positive noise from PyInstaller bundles and common AI framework patterns, and validate anything CAIRN surfaces with proper reverse engineering rather than trusting metadata alone. Treated as a lead generator for threat-intelligence and detection teams, it offers something scarce: a shared, open way to watch an emerging category grow before it becomes a mainstream problem.

It fits a healthy pattern of open defensive tooling for the AI era, alongside projects like Cisco's DefenseClaw framework for securing AI agents. Follow more defensive research in our AI security coverage.

Sources: Cisco Talos — September 22, 2026; Help Net Security — September 22, 2026; CAIRN on GitHub — September 22, 2026.

More Ai Security Stories