Threats

JadePuffer Ransomware Employs AI Agent for Automated Attacks

July 4, 2026 20:01 · 12 min read
JadePuffer Ransomware Employs AI Agent for Automated Attacks

Researchers at Sysdig, a cloud security company, have identified a ransomware operation, known as JadePuffer, which is believed to be the first documented case of a ransomware attack conducted entirely by a large language model (LLM) agent.

JadePuffer's Autonomous AI Agent

The JadePuffer ransomware uses an autonomous AI agent for reconnaissance on the target, to steal credentials, move laterally, establish persistence, escalate privileges, and to encrypt data. This agent adapts to failures during the intrusion, much like a human operator would handle obstacles.

According to Sysdig, the AI agent adapted in real-time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds. This level of adaptability and rapid iteration is a significant concern for security teams.

Exploitation of CVE-2025-3248

JadePuffer gained initial access to the target by exploiting CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow, a popular open-source framework used for building LLM apps. The vendor fixed the flaw on April 1, 2025, and in early May of the same year, CISA tagged it as exploited in attacks targeting internet-exposed endpoints.

After obtaining code execution through CVE-2025-3248, the AI agent dumped Langflow's PostgreSQL database, collected host information, searched for environment variables and sensitive files, retrieved credentials, and enumerated a MinIO object store. The agent's approach to MinIO enumeration was notably adaptive, adjusting its parsing logic if one API request returned XML instead of JSON.

Persistence and Lateral Movement

JadePuffer established persistence on the Langflow host by installing a cron job on the server, which was configured to beacon to the attacker’s infrastructure every 30 minutes. From the Langflow instance, the attacker pivoted to a production MySQL server running Alibaba Nacos (Naming and Configuration Service), using root credentials whose origin Sysdig couldn’t determine.

Nacos was targeted with multiple payloads, including one exploiting CVE-2021-29441, an authentication bypass vulnerability that creates rogue administrator accounts. The agent probed for container escape methods and deployed the ransomware payload.

Encryption and Ransom Demand

According to the researchers, JadePuffer encrypted 1,342 Nacos service configuration items before deleting the originals. The captured payloads show the agent encrypting all 1,342 Nacos service configuration items using MySQL's AES_ENCRYPT(), dropping the original config_info and history tables, and creating an extortion table (README_RANSOM) containing the demand, a Bitcoin payment address, and a Proton Mail contact.

The ransom note claims that the data was encrypted using the AES-256 algorithm, although the researchers believe this to be an overstatement, and that the use of the weaker AES-128-ECB is more likely. The encryption key is randomly generated but not stored or transmitted to the attacker.

Implications and Detection Opportunities

Sysdig concludes that the case of JadePuffer demonstrates that the age of “agentic threat actors” (ATAs) has arrived, lowering the skill required for conducting damaging cyberattacks. At the same time, given how AI agents operate today, LLM-generated payloads create new detection opportunities for security solutions.

Security teams are advised to test every layer before attackers do, as the Picus whitepaper shows how breach and attack simulation tests SIEM and EDR rules so threats stop slipping by detection.

It's essential for organizations to understand the evolving threat landscape and adapt their security strategies to include the detection and mitigation of AI-driven attacks like JadePuffer.

Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The arrival of agentic threat actors like JadePuffer underscores the need for robust security measures that can detect and respond to AI-driven attacks, ensuring the protection of critical data and systems.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free