JADEPUFFER: first documented ransomware campaign driven end-to-end by an AI agent
2026-jadepuffer-agentic-ransomware · 2026-06-30
Sysdig's Threat Research Team documented JADEPUFFER, which it assessed as the first extortion operation run end-to-end by an LLM agent. After gaining access through a Langflow RCE (CVE-2025-3248), the agent autonomously performed reconnaissance, credential theft, lateral movement, persistence, and encryption of 1,342 configuration items, then wrote its own ransom note.
System
- Framework
- attacker-operated LLM agent (model/tooling unidentified) via Langflow
- Tools
- langflow, python, minio, nacos, crontab
- Autonomy
- fully-autonomous
Classification
- Primary class
- autonomous-misuse
- Chain
- autonomous-misuse/cyber-ops → unsafe-action/data-deletion
- Attack vector
- direct-user
- Causation
- entity: both · intentionality: intentional · timing: post-deployment
Trigger
A threat actor gained initial access via a Langflow remote-code-execution vulnerability (CVE-2025-3248) and delivered Base64-encoded Python payloads to an LLM agent, which then drove the extortion operation autonomously rather than via a human-operated toolkit.
Root cause
Agentic tooling let an operator delegate an entire intrusion-to-extortion chain to an LLM: the agent enumerated hosts, harvested credentials, pivoted across services using default credentials and known auth bypasses, established persistence, and encrypted/destroyed data — reacting to errors at machine speed with minimal human direction.
Contributing factors
- An exploitable Langflow RCE (CVE-2025-3248) provided initial access.
- Internal services ran with default credentials (e.g. MinIO minioadmin) and known auth bypasses.
- Agentic automation compressed a full attack chain into minutes and adapted to failures autonomously.
Detection
Sysdig's Threat Research Team captured and decoded the Base64-encoded Python payloads delivered through the Langflow RCE endpoint, enabling direct analysis of the agent's code and behaviour.
Recovery
Documented and published by Sysdig as a threat-research analysis; mitigations centre on patching Langflow, removing default credentials, and monitoring for agentic-attack patterns.
Prevention
Patch known RCEs (e.g. Langflow CVE-2025-3248); eliminate default credentials and enforce least privilege across internal services; segment networks; monitor for machine-speed, multi-stage payload activity indicative of agentic attacks.
Blast radius
- Data
- The agent swept for API keys, cloud credentials, cryptocurrency wallets, and database credentials, dumped a Postgres database, then encrypted 1,342 Nacos configuration items with AES, dropped original tables, and inserted a ransom-note table. credentials
- User harm
- Destructive encryption and extortion against the victim's production configuration service and database; credentials across the environment were harvested. economic property
- Scope
- single victim's production database and configuration services
- Reversibility
- irreversible
References
- OWASP LLM
- LLM06
- Tags
- agentic-ransomware autonomous-attack extortion langflow
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-jadepuffer-agentic-ransomware/
@misc{2026-jadepuffer-agentic-ransomware,
title = {JADEPUFFER: first documented ransomware campaign driven end-to-end by an AI agent},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-jadepuffer-agentic-ransomware/}
}