Traces left when malware borrows a language model can now be classified out in the open. Cisco Talos shipped a framework on Monday that reads those artifacts out of sample metadata, hands each one an identifier, and groups them by shared traits. Researchers named it CAIRN, after the stacked stones hikers use to mark a path, short for Cognitive Artifact Intelligence Research Network.
Comparing the resulting library is where the value sits, since neighbors in it expose connections and emerging patterns across otherwise unrelated samples.
What that hunt found was striking: CLOSEDQUORUM, a hacking tool with fully autonomous command-and-control. It mapped its next move inside a victim network by polling up to four large language models and following the consensus. Ryan Fetterman, the Talos researcher behind the work, compares those traces to fingerprints, saying they give defenders a way to track samples and spot emergent behavior.
The field looked thin before the framework existed. Ukraine’s CERT-UA flagged an implant named LAMEHUG in July 2025 that pulled commands from Qwen2.5-Coder-32B-Instruct over a Hugging Face interface. Reviewing a year of reporting, Fetterman could name only about nine families, several of them research proofs of concept. Months of CAIRN use have since added roughly 20 examples, and he argues the real landscape is more varied than anything published so far.