Researchers found malware that uses four different AI chatbots to run itself
TechSpot

Researchers found malware that uses four different AI chatbots to run itself

Looking ahead: Researchers at Cisco Talos have found a Windows malware tool that uses several large language models to help decide what to do on a compromised machine. Its discovery points to a still-limited but growing group of AI-enabled malware that is moving beyond code generation and phishing support. The finding also gives defenders an early look at how attackers may build more autonomous and resilient command-and-control systems. The malware, called CLOSEDQUORUM, checks with DeepSeek, Qwen, Mistral and Google Gemini before selecting its next action. It can continue operating if one of those services is unavailable because it can query the others. Cisco Talos said the tool has no built-in path for a human operator to issue commands once it is running. Researchers said CLOSEDQUORUM is built to steal login credentials and cryptocurrency. They identified links between the malware and cybercrime forum activity involving credit-card fraud dating to 2025. Talos could not determine who created the tool or whether it has been used against real targets. The discovery came through a new Cisco Talos project meant to help security researchers track malware that relies on AI services. The open-source framework, called the Cognitive Artifact Intelligence Research Network, or CAIRN, looks for technical traces associated with AI use in malware samples. "The core idea is that AI integration has these vestiges, like fingerprints, that are left behind," Ryan Fetterman, a Cisco Talos security researcher who led development of CAIRN, told Wired. "That gives us a signal that we can use to track these samples, classify them, and look at what's happening." CAIRN examines metadata and other attributes tied to AI integrations, then gives samples an identifier that researchers can use to compare them with other known malware. The system groups artifacts with similar traits, helping analysts identify patterns in how attackers are adding LLMs to malware and command-and-control operations. The key difference with CLOSEDQUORUM is its use of LLMs as part of the control system itself. Earlier AI-related malware examples have often involved attackers using models to write code, create phishing content or automate parts of a campaign. CLOSEDQUORUM instead uses model responses to guide its actions after it reaches a target system. Matt Olney, senior director of threat intelligence at Cisco Talos, said that shift shows AI moving from a support tool to a component of attack infrastructure. "Initially, everyone saw AI as a productivity tool, right?" Olney said. "Now what we're seeing is that it's becoming operationalized. So for attackers, it's allowing them to run more campaigns, hit more spaces, handle more and different computers, because they have this very intelligent box in the backend that can ask questions and give responses." Talos developed CAIRN after Fetterman reviewed publicly documented examples of malware using AI. One early case was LAMEHUG, malware that Ukraine's CERT-UA linked to a phishing campaign in July 2025. The implant contacted Qwen2.5-Coder-32B-Instruct through a Hugging Face API to obtain commands. "At the time I was like, 'Wow, this is amazing. There's gonna be this big boom of AI-enabled malware and the landscape is totally going to change,'" Fetterman said. But when Fetterman reviewed the field about a year later, he found far fewer documented cases than expected. He identified roughly nine named malware families, including some research proofs of concept. CAIRN has since revealed a broader set of samples. Fetterman said he found about 20 additional examples of AI-integrated malware while developing and testing the framework. The activity remains largely experimental, he said, but the additional samples show that public reporting has not captured the full range of AI-enabled malware under development. "So while I do think this is still largely experimental for attackers, the landscape is a lot more complex and diverse than has been publicly reported," Fetterman said. "There's a lot going on out there, and it does provide a valuable early signal to what's going to happen."

Read on TechSpot ↗ ← Back to News

Comments

No comments yet. Start the discussion.