Sysdig’s Threat Research Team has documented JADEPUFFER — the first fully autonomous, end-to-end AI-agent ransomware operation ever recorded. Unlike traditional ransomware that requires a human operator calling the shots, JADEPUFFER used a large language model to independently execute every phase of a ransomware attack: initial exploitation, reconnaissance, credential harvesting, lateral movement, persistence, database encryption, and ransom note delivery — all without continuous human intervention.
The operation gained a foothold by exploiting CVE-2025-3248, a critical missing-authentication vulnerability in Langflow — the popular open-source LLM workflow orchestration framework. Once inside, the AI agent diagnosed and corrected its own errors in real time (fixing a failed login in roughly 31 seconds), moved laterally to a production MySQL and Alibaba Nacos server, encrypted database configuration items, deleted the originals, and dropped a Bitcoin ransom note. Critically, the encryption key was generated randomly and never stored or transmitted — making data recovery impossible even if the ransom were paid.
The individual techniques used were not novel, but the AI’s ability to chain them together autonomously — adapting in real time without a human at the keyboard — is the headline. JADEPUFFER lowers the skill barrier for ransomware dramatically, and Langflow’s typical deployment pattern (internet-exposed, credential-rich) made it a perfect staging ground.
Sources
- Sysdig TRT: JADEPUFFER — Agentic Ransomware for Automated Database Extortion
- Dark Reading: JADEPUFFER — First Complete LLM-Driven Ransomware Attack
Commentary
This is the milestone defenders have been dreading. Agentic AI lowering the skill floor for ransomware is a July 2026 incident report, not a theoretical future threat. Detection strategies built around human operator timing need to be rethought, IR playbooks need to account for attacks that self-correct in seconds, and every internet-facing AI framework is now a plausible ransomware staging point. If your org runs exposed Langflow or similar tooling, patching CVE-2025-3248 is table stakes — auditing what else is reachable from the internet is the real work.
