AI

Hive-mind C2: malware that asks four AIs what to do next

· Geeknewz Author

Circuit board with glowing microchip traces

Original Geeknewz editorial — analysis from public Cisco Talos research and reporting (including WIRED), not a single-outlet rewrite.

Most malware still phones home like a needy intern: “Boss, I dumped LSASS—what next?” Cisco Talos just spotlighted a nastier career path. Meet CLOSEDQUORUM, Windows malware that treats four commercial AIs as its board of directors—and does not invite a human to the meeting.

Green cascading code on a dark screen
Photo via Unsplash (https://unsplash.com/photos/1526374965328-7f61d4dc18c5). Unsplash License.

On September 22, 2026, Talos open-sourced CAIRN (Cognitive Artifact Intelligence Research Network), a toolkit for hunting malware that operationalizes AI. CAIRN looks for the digital cairns attackers leave behind: provider endpoints, prompt templates, API-key shaped strings, tool-call syntax, and other “cognitive artifacts” in metadata. Lead researcher Ryan Fetterman framed the idea cleanly for WIRED: AI integration leaves vestiges—fingerprints you can track, classify, and map without babysitting every binary by hand.

From LAMEHUG curiosity to a hunting stack

The vibe check starts in July 2025. Ukraine’s CERT-UA flagged LAMEHUG, phishing malware that talked to Qwen through a Hugging Face API for instructions. Fetterman expected a stampede. A year later, a retrospective still only surfaced roughly nine named families—including research proofs of concept. That mismatch is why CAIRN exists: if the public catalog looked quiet, maybe the hunting method was the bottleneck.

Illuminated server racks in a data center
Photo via Unsplash (https://unsplash.com/photos/1558494949-ef010cbdcc31). Unsplash License.

After months with CAIRN, Fetterman told WIRED he had found about twenty more AI-integrated samples. Still experimental for many actors, he argued—but messier and more diverse than the headline count suggested. That is the defensive value of an early-warning system: not apocalypse theater, but a map of what attackers are actually trying while the genre is still weird.

CLOSEDQUORUM: quorum means vote, closed means no humans

CLOSEDQUORUM is the showpiece finding. Talos describes it as, to its knowledge, the first publicly documented Windows implant to hand tactical command-and-control to a multi-model panel. The quorum can include DeepSeek, Qwen, Mistral, and Google Gemini. Models are queried in sequence; their decisions are tallied; plurality wins. If one provider is down, rate-limited, or mid-refusal, the others still vote. The session is closed: there is no live human tasking loop and no classic attacker-owned C2 listener for the decision phase.

Why that matters for defenders: traditional C2 means a domain, an IP, a protocol, and a paper trail. CLOSEDQUORUM’s “infrastructure” looks like ordinary LLM APIs that thousands of legit apps hit daily. Blocking api.deepseek.com is not a free lunch when your developers also need it. Detection has to get behavioral—API chatter from a weird Windows binary, clustered calls to several model vendors, then LSASS/browser/wallet theft in the same process family.

Capability-wise, the public research paints a credential-and-crypto heist machine: dump secrets, grab browser logins, scoop wallet material. Talos connected artifacts to carding-forum activity going back to 2025, but could not confirm the author or real-world attack success. Important caveat from Talos itself: the public distribution build ships with placeholder API keys and a dummy webhook, so researchers did not watch a fully live end-to-end run of the hive mind. Treat it as a concrete architecture demo with criminal-ecosystem breadcrumbs—not as confirmed mass exploitation.

Effort displacement, not just faster phishing

Talos’ framing is sharper than “AI writes scarier emails.” Speed and scale already happened. The third axis is effort displacement: moving a whole attack phase off the operator’s calendar. Humans sleep. Quorums do not. Matt Olney, senior director of threat intelligence at Cisco Talos, told WIRED the shift is from AI-as-productivity-tool to AI becoming operationalized—letting attackers run more campaigns across more machines because an intelligent backend can ask questions and return executable answers.

CLOSEDQUORUM also shows the trade: autonomy inherits model failure modes. Refusals, malformed JSON, rate limits, and deterministic tie-breakers (Talos notes DeepSeek-first bias on ties) are attack-surface for defenders as much as features for crooks. Constraining the models to a typed decision schema—steal, inject, persist, and friends—makes the implant more reliable for attackers and more patternable for detection engineers.

Geeknewz read

CAIRN is not a panic button; it is trail markers for a path that just got clearer. LAMEHUG was a chatbot on a leash. CLOSEDQUORUM is a committee that can keep working after the operator closes Discord. Open-sourcing the hunting methodology is the adult move: if AI-integrated malware is still mostly experimental, this is exactly when defenders should learn the artifacts, graph the relationships, and practice detections that do not assume a single evil domain.

The hive mind is not magic. It is four APIs and a vote counter. That is plenty scary—and plenty observable—if we start looking for the cairns.