
Fetterman called CLOSEDQUORUM a credentials-as-a-service model, and noted that a human operator who acquires the malware does not need to be online to run their campaign. “They deploy the binary, and the LLM panel runs the attack,” he said. “This type of scaffolding approach could easily be translated and applied to other adversary objectives.”
A ‘fleeting window’ of AI transition
Cisco Talos discovered CLOSEDQUORUM with its new CAIRN open-source research toolkit for hunting, classifying, and tracking AI-integrated malware. Released today, CAIRN is “metadata-first,” and can craft structured graphs of artifact relationships to help human defenders identify related malware families and infrastructure.
Malware samples are sent to VirusTotal, which extracts and indexes static, dynamic, reputation, and behavioral metadata. AI-related artifacts are surfaced from content, behavior, URLs, labels, and resource metadata, and 12 targeted filters capture different classes of artifacts (APIs, prompts, frameworks, tooling, runtimes).
