Cisco Talos researchers released CAIRN, a framework to classify AI-integrated malware, after identifying a tool named CLOSEDQUORUM in July 2025. It is the company's first major update to its cybersecurity tools since the discovery of the LAMEHUG malware in 2025.

Cisco Talos reported that CAIRN has identified about 20 additional examples of AI-integrated malware since its development, measured on the framework's ability to flag AI-integration characteristics. That compares with only nine named malware families previously documented by researchers.

CAIRN is built on a metadata analysis system and targets the classification of AI-integrated malware. Availability begins with open-source release, initially for cybersecurity researchers and practitioners.

"The core idea is that AI integration has these vestiges, like fingerprints, that are left behind," said Ryan Fetterman, a security researcher at Cisco Talos who led development of CAIRN. Fetterman added that CAIR, the framework, gives us a signal that we can use to track these samples, classify them, and look at what's happening.

The announcement follows a July 2025 warning by the Ukrainian cybersecurity response unit CERT-UA about a phishing campaign using malware known as LAMEHUG. Cisco Talos researchers noted that the landscape of AI-enabled malware is more complex and diverse than publicly reported.

Cisco Talos did not say who developed the CLOSEDQUORUM malware or whether it has been used in real-world attacks, and raised the open question of how much of the AI-integrated malware landscape remains unreported. The researchers could not confirm the malware's real-world usage.

Source: wired