BlackTree Security · Infrastructure · Automation · AI

Cisco Found a New Way to Hunt Malware by the Prompts It Leaves Behind

Malware that calls an AI model leaves behind a surprisingly human weakness: it has to describe what it wants. Cisco Talos has released an open-source research toolkit that hunts for those instructions, the API artefacts around them and the syntax used to invoke tools.

The toolkit is called CAIRN. It analyses metadata and extracted artefacts without downloading or executing the original binary, then combines YARA matching, semantic clustering and relationship graphs to help researchers find samples that share AI-related behaviour.

Prompts are becoming malware artefacts

Traditional malware analysis looks for code, infrastructure, configuration and behaviour. AI-integrated malware adds another layer: system prompts, model endpoints, tool definitions, function names and instructions describing reconnaissance, evasion or data handling.

Those artefacts can survive code changes because the model still needs enough context to perform the requested task. CAIRN uses exact rules where the language is distinctive and semantic similarity where attackers can paraphrase the same intent.

Cisco Talos used the method to describe CLOSEDQUORUM, the first family surfaced through the project. That does not mean every sample mentioning an AI service is malicious, nor that prompt similarity alone proves a shared operator. The toolkit is intended to produce research leads that still require analyst validation.

Why defenders should care

  • AI use creates new indicators. Model endpoints, SDK strings, prompt fragments and tool schemas can complement conventional detections.
  • Semantic rules can outlast wording changes. They may identify related intent when an operator rewrites a prompt, although they also need careful tuning and review.
  • Relationship graphs reveal clusters. Shared infrastructure, prompt language and implementation details can expose families that a single hash or signature would miss.
  • Safe triage can happen earlier. Working from extracted artefacts reduces the need to execute every candidate during the first research pass.

CAIRN is not a replacement for sandboxing, reverse engineering or endpoint telemetry. Its value lies in recognising that AI has given malware a new interface and, with it, a new trail of evidence.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *