Cisco Talos releases CAIRN open-source tool for hunting malware that uses AI services
Security Tool/Service
Summary
Hide ▲
Show ▼
Cisco Talos released CAIRN, an open-source tool that hunts malware that uses AI services, adding a new detection capability for implants that route decisions through commercial AI platforms. The release matters because it gives defenders a dedicated way to spot a growing malware technique that can blend into normal cloud and AI traffic.
Related Happenings
CLOSEDQUORUM Windows AI-model-voting malware
Malware Activity
H score29
First: 23.09.2026 17:17
Last: 23.09.2026 17:17
Sources 1
How related:
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22.
About this happening:
The CLOSEDQUORUM malware now uses votes from up to four AI models to choose steal, inject, persist, or move actions, replacing a normal attacker C2 flow on Windows...
CLOSEDQUORUM Windows AI-model-voting malware
Malware ActivityHow related: A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22.
About this happening: The CLOSEDQUORUM malware now uses votes from up to four AI models to choose steal, inject, persist, or move actions, replacing a normal attacker C2 flow on Windows...
UAT-11795 Starland RAT trojanized installer malware activity
Malware Activity
H score31
First: 16.07.2026 13:19
Last: 16.07.2026 13:19
Sources 1
About this happening:
The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....
UAT-11795 Starland RAT trojanized installer malware activity
Malware ActivityAbout this happening: The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....
RondoDox botnet expands mining and DDoS capabilities
Malware Activity
H score31
First: 16.04.2026 20:52
Last: 16.04.2026 20:52
Sources 1
About this happening:
RondoDox botnet now combines cryptocurrency mining with XMRig and DDoS attacks, expanding both monetization and disruption risk across exposed systems. It reaches targ...
RondoDox botnet expands mining and DDoS capabilities
Malware ActivityAbout this happening: RondoDox botnet now combines cryptocurrency mining with XMRig and DDoS attacks, expanding both monetization and disruption risk across exposed systems. It reaches targ...
UAT-9244 South America telecom targeting campaign
Campaign
H score33
First: 06.03.2026 01:19
Last: 06.03.2026 01:19
Sources 1
About this happening:
UAT-9244 is a China-linked campaign targeting telecommunication providers in South America since 2024. It compromises Windows, Linux, and edge devices to expand access across tele...
UAT-9244 South America telecom targeting campaign
CampaignAbout this happening: UAT-9244 is a China-linked campaign targeting telecommunication providers in South America since 2024. It compromises Windows, Linux, and edge devices to expand access across tele...
Latest development: 06.03.2026 10:22
The first documented phase centers on TernDoor targeting Windows hosts through DLL side-loading with `wsprint.exe` and `BugSplatRc64.dll`. After launch, it loads in memory and establishes persistence through a scheduled task or the Registry Run key.
VoidLink Linux C2 malware activity
Malware Activity
H score28
First: 09.02.2026 17:25
Last: 09.02.2026 17:25
Sources 1
About this happening:
VoidLink is an operational Linux C2 framework used by UAT-9921 as a post-compromise tool against technology and financial services targets. Cisco Talos says th...
VoidLink Linux C2 malware activity
Malware ActivityAbout this happening: VoidLink is an operational Linux C2 framework used by UAT-9921 as a post-compromise tool against technology and financial services targets. Cisco Talos says th...
Timeline
-
23.09.2026 17:17 2 articles · 2h ago
Cisco Talos releases CAIRN open-source malware hunting tool
Detection Ioc UpdateCisco Talos released CAIRN, an open-source tool for hunting malware that uses AI services, and used it to find CLOSEDQUORUM.
Show sources
- This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move — thehackernews.com — 23.09.2026 17:17
- This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move — thehackernews.com — 23.09.2026 17:17