For years, cybersecurity practitioners have tracked different types of malware and detected potential infections using digital fingerprints to identify different hacking tools and follow their use over time. As attackers are increasingly incorporating agentic AI components into their hacking tools, researchers from Cisco Talos shared an open-source framework on Monday that they hope will be used widely to classify and analyze AI-integrated malware. They also have proof that it's already working.
\n\nThey're calling the framework Cognitive Artifact Intelligence Research Network, or CAIRN, named after the stacks of stones that hikers set up on trails to mark the path or emphasize something about a certain spot. As malware authors expand their use of AI services, Cisco Talos researchers have used CAIRN to identify a hacking tool with fully autonomous command-and-control infrastructure. Dubbed CLOSEDQUORUM, the malware plotted its moves within a target system by polling up to four large language models (LLMs) about what it should do and taking its directives from that hive mind.
\n\n“The core idea is that AI integration has these vestiges, like fingerprints, that are left behind,” says Ryan Fetterman, a security researcher at Cisco Talos who led development of CAIRN. “That gives us a signal that we…
Original source: https://www.wired.com/