메뉴
BL
Wired AI • 4일 전

AI 집단지성이 스스로 명령 내리는 악성코드 발견한 새 도구

IMP
8/10
핵심 요약

시스코 탈로스(Cisco Talos)가 AI 통합 악성코드를 분류·분석하는 오픈소스 프레임워크 'CAIRN'을 공개했습니다. 이 도구는 사람의 개입 없이 최대 4개의 대규모 언어모델(LLM)에 다음 행동을 질의해 합의에 따라 움직이는 완전 자율적 명령제어(C2) 구조의 'CLOSEDQUORUM' 악성코드를 발견했습니다. AI 통합 악성코드는 아직 실험 단계지만 공개 보도보다 훨씬 다양하게 존재하며, 방어 커뮤니티에 중요한 조기 경고 신호가 됩니다.

번역된 본문

수년간 사이버보안 실무자들은 디지털 지문을 이용해 다양한 해킹 도구를 식별하고 그 사용을 시간에 따라 추적하며 악성코드를 감지해 왔다. 공격자들이 에이전틱 AI 구성 요소를 해킹 도구에 점점 더 통합함에 따라, 시스코 탈로스(Cisco Talos)의 연구자들은 월요일 AI 통합 악성코드를 분류하고 분석하는 데 널리 사용되기를 희망하는 오픈소스 프레임워크를 공개했다. 그리고 이것이 이미 효과를 보고 있다는 증거도 갖고 있다.

이 프레임워크의 이름은 '코그너티브 아티팩트 인텔리전스 리서치 네트워크(Cognitive Artifact Intelligence Research Network, CAIRN)'로, 등산객이 산길에 쌓아두는 돌탑(케언)에서 따온 것이다. 돌탑은 길을 표시하거나 특정 지점을 강조하기 위해 세워진다. 악성코드 제작자들의 AI 서비스 활용이 확대되면서, 시스코 탈로스 연구진은 CAIRN을 통해 완전히 자율적인 명령제어(C2) 인프라를 갖춘 해킹 도구를 식별해냈다. 'CLOSEDQUORUM'이라 명명된 이 악성코드는 표적 시스템 안에서 다음 행동을 결정하기 위해 최대 4개의 대규모 언어모델(LLM)에 질의를 던지고, 그 집단지능(hive mind)의 판단을 지시로 삼아 움직였다.

“핵심 아이디어는 AI 통합이 지문처럼 흔적을 남긴다는 것입니다.” CAIRN 개발을 이끈 시스코 탈로스의 보안 연구자 라이언 페터먼(Ryan Fetterman)은 말한다. “그것이 우리가 이 샘플들을 추적하고, 분류하고, 무슨 일이 일어나는지 살펴볼 수 있는 신호를 줍니다. 공격자들이 무엇을 시도하고 있나요? 어떤 창발적 행동이 나타나고 있나요? 이런 것들이 대중화되어 가는 지금, 방어 커뮤니티에 귀중한 자원이 됩니다.”

2025년 7월, 우크라이나 사이버보안 대응기관 CERT-UA는 'LAMEHUG'라는 악성코드를 사용하는 피싱 캠페인을 감지했다고 경고했다. 이 임플란트(침투 도구)는 휴깅페이스(Hugging Face) API를 통해 Qwen2.5-Coder-32B-Instruct라는 LLM과 통신하며 명령을 받았다.

“그때 저는 '와, 대단하다. AI 기반 악성코드의 큰 붐이 올 것이고 공격 양상이 완전히 바뀌겠구나'라고 생각했습니다.” 페터먼은 말한다. 하지만 1년 뒤인 올여름 AI를 통합한 악성코드를 회고 정리하려고 했을 때, 그는 문서화된 사례가 여전히 몇 건에 불과하다는 사실에 충격을 받았다. “정말 많지 않았습니다. 이름 붙은 악성코드 패밀리를 대략 9개 정도 찾았는데, 그중 일부는 연구용으로 만들어진 개념 증명(PoC)이었습니다. 예상과 달랐고, 그게 현실이라는 걸 받아들이기 어려웠죠. 그래서 파고들기 시작했습니다.”

그 결과물이 CAIRN이다. CAIRN은 메타데이터에서 AI 통합 특성과 속성을 식별하고, 이를 통해 악성코드 샘플에 사실상 고유 ID를 부여해 분류하고 태그를 붙이도록 설계됐다. 이 시스템은 각 아티팩트를 CAIRN 라이브러리의 모든 자료와 비교·분석하고 다양한 특성별로 그룹화하여 잠재적 추세와 연관성을 보여준다.

페터먼은 지난 몇 달간 CAIRN을 개발하고 사용하면서 AI 통합 악성코드의 추가 사례 약 20건을 발견했다고 말한다. “그래서 공격자들에게 이것이 여전히 대체로 실험적이라고 생각하지만, 실제 양상은 공개 보도된 것보다 훨씬 복잡하고 다양합니다. 밖에서는 많은 일이 벌어지고 있고, 앞으로 무슨 일이 일어날지에 대한 귀중한 조기 신호가 됩니다.”

CAIRN이 식별한 CLOSEDQUORUM 해킹 도구는 윈도우 악성코드로, 딥시크(DeepSeek), Qwen, Mistral, 구글 제미나이(Gemini)에 질의해 다음 단계에 대한 합의를 도출한다. 하나의 AI 서비스를 사용할 수 없어도 나머지에 계속 질의하므로 충분한 이중화가 이뤄지며, 시스템이 완전히 폐쇄적이고 인간의 입력 메커니즘이 전혀 없다. 시스코 탈로스 연구진은 이 악성코드와 2025년으로 거슬러 올라가는 신용카드 사기 관련 사이버범죄 포럼 사이의 일부 연결고리를 확인했으며, 이 악성코드는 로그인 자격증명과 암호화폐를 탈취하도록 설계되었다. 연구진은 배후 세력이 누구인지는 확인하지 못했다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story For years, cybersecurity practitioners have tracked different types of malware and detected potential infections using digital fingerprints to identify different hacking tools and follow their use over time. As attackers are increasingly incorporating agentic AI components into their hacking tools, researchers from Cisco Talos shared an open-source framework on Monday that they hope will be used widely to classify and analyze AI-integrated malware . They also have proof that it's already working. They're calling the framework Cognitive Artifact Intelligence Research Network, or CAIRN , named after the stacks of stones that hikers set up on trails to mark the path or emphasize something about a certain spot. As malware authors expand their use of AI services, Cisco Talos researchers have used CAIRN to identify a hacking tool with fully autonomous command-and-control infrastructure. Dubbed CLOSEDQUORUM , the malware plotted its moves within a target system by polling up to four large language models (LLMs) about what it should do and taking its directives from that hive mind. “The core idea is that AI integration has these vestiges, like fingerprints, that are left behind,” says Ryan Fetterman, a security researcher at Cisco Talos who led development of CAIRN. “That gives us a signal that we can use to track these samples, classify them, and look at what's happening. What are attackers trying? What kind of emergent behaviors are we seeing? That's a valuable resource to the defensive community as these things become more mainstream.” In July 2025, the Ukrainian cybersecurity response unit CERT-UA warned about a phishing campaign it had detected using malware known as “LAMEHUG.” The implant communicated with an LLM called Qwen2.5-Coder-32B-Instruct through a Hugging Face API to get commands. “At the time I was like, ‘Wow, this is amazing. There’s gonna be this big boom of AI-enabled malware and the landscape is totally going to change,’” Fetterman says. A year later, though, when he went to do a retrospective this summer of malware integrating AI, Fetterman was shocked that he could still only find a few documented examples. “There really wasn't a lot there. I think I came up with maybe nine different named malware families,” and some of those were proofs of concept created for research, he says. “It just wasn't what I was expecting, and I think I also had a hard time believing that that was the reality of where we were. So I wanted to start digging into that.” The result is CAIRN, which is designed to flag AI-integration characteristics and attributes from metadata, and use this to classify and tag malware samples with, essentially, a unique ID. The system then analyzes each artifact in the context of everything in the CAIRN library and groups them by various traits to illustrate potential trends and connections. Fetterman says that after working on and using CAIRN for the past few months, he has discovered about 20 additional examples of AI-integrated malware. “So while I do think this is still largely experimental for attackers, the landscape is a lot more complex and diverse than has been publicly reported,” he says. “There's a lot going on out there, and it does provide a valuable early signal to what's going to happen.” The CLOSEDQUORUM hacking tool that CAIRN identified is Windows malware that checks with DeepSeek, Qwen, Mistral, and Google Gemini to develop a consensus on what its next steps should be. Even if one AI service is unavailable, the malware still polls the others, creating enough redundancy that the system is totally closed and has no mechanism for human input. Cisco Talos researchers saw some links between the malware and cybercriminal forums about credit card fraud going back to 2025, and it is designed to steal login credentials and cryptocurrency. The researchers could not confirm who developed the malware, though, or whether it has actually been used in real-world attacks. “Initially, everyone saw AI as a productivity tool, right?” says Matt Olney, senior director of threat intelligence at Cisco Talos, referring to both legitimate work and malicious hacking. “Now what we're seeing is that it's becoming operationalized. So for attackers, it's allowing them to run more campaigns, hit more spaces, handle more and different computers, because they have this very intelligent box in the backend that can ask questions and give responses.”