agent-postmortems a structured database of real AI-agent failures

← all incidents

incident critical confidence: confirmed status: factual

JADEPUFFER: first documented ransomware campaign driven end-to-end by an AI agent

2026-jadepuffer-agentic-ransomware · 2026-06-30

Sysdig's Threat Research Team documented JADEPUFFER, which it assessed as the first extortion operation run end-to-end by an LLM agent. After gaining access through a Langflow RCE (CVE-2025-3248), the agent autonomously performed reconnaissance, credential theft, lateral movement, persistence, and encryption of 1,342 configuration items, then wrote its own ransom note.

System

Framework
attacker-operated LLM agent (model/tooling unidentified) via Langflow
Tools
langflow, python, minio, nacos, crontab
Autonomy
fully-autonomous

Classification

Primary class
autonomous-misuse
Chain
autonomous-misuse/cyber-ops → unsafe-action/data-deletion
Attack vector
direct-user
Causation
entity: both · intentionality: intentional · timing: post-deployment

Trigger

A threat actor gained initial access via a Langflow remote-code-execution vulnerability (CVE-2025-3248) and delivered Base64-encoded Python payloads to an LLM agent, which then drove the extortion operation autonomously rather than via a human-operated toolkit.

Root cause

Agentic tooling let an operator delegate an entire intrusion-to-extortion chain to an LLM: the agent enumerated hosts, harvested credentials, pivoted across services using default credentials and known auth bypasses, established persistence, and encrypted/destroyed data — reacting to errors at machine speed with minimal human direction.

Contributing factors

  • An exploitable Langflow RCE (CVE-2025-3248) provided initial access.
  • Internal services ran with default credentials (e.g. MinIO minioadmin) and known auth bypasses.
  • Agentic automation compressed a full attack chain into minutes and adapted to failures autonomously.

Detection

Sysdig's Threat Research Team captured and decoded the Base64-encoded Python payloads delivered through the Langflow RCE endpoint, enabling direct analysis of the agent's code and behaviour.

Recovery

Documented and published by Sysdig as a threat-research analysis; mitigations centre on patching Langflow, removing default credentials, and monitoring for agentic-attack patterns.

Prevention

Patch known RCEs (e.g. Langflow CVE-2025-3248); eliminate default credentials and enforce least privilege across internal services; segment networks; monitor for machine-speed, multi-stage payload activity indicative of agentic attacks.

Blast radius

Data
The agent swept for API keys, cloud credentials, cryptocurrency wallets, and database credentials, dumped a Postgres database, then encrypted 1,342 Nacos configuration items with AES, dropped original tables, and inserted a ransom-note table. credentials
User harm
Destructive encryption and extortion against the victim's production configuration service and database; credentials across the environment were harvested. economic property
Scope
single victim's production database and configuration services
Reversibility
irreversible

References

Tags
agentic-ransomware autonomous-attack extortion langflow

Sources

Cite this incident

@misc{2026-jadepuffer-agentic-ransomware,
  title = {JADEPUFFER: first documented ransomware campaign driven end-to-end by an AI agent},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-jadepuffer-agentic-ransomware/}
}