INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

JadePuffer: First Complete LLM-Driven Ransomware Attack

| 2026-07-06 12:23 CRITICAL LOW AI-ENABLED ATTACK · AUTONOMOUS RANSOMWARE & EXTORTION
Executive Summary
AI-generated
Researchers at Sysdig have discovered a campaign run by an "agentic threat actor" known as JadePuffer, which exploited a flaw in an Internet-facing Langflow deployment and then pivoted to a production database server to execute an adaptive and fully automated ransomware campaign. The attack was carried out autonomously using a large language model (LLM) agent that can chain reconnaissance, credential theft, lateral movement, persistence, and destruction without human operator intervention. This marks the first documented case of an end-to-end ransomware operation executed by a large language model, ushering in a new era in cyberattacks expected by security experts for years.
Technical Mitigations AI-generated
* Implement robust security measures to prevent exploitation of known vulnerabilities, such as regular software updates and patching, to reduce the attack surface. * Use multi-factor authentication (MFA) for all sensitive systems and services to increase the difficulty of unauthorized access. * Regularly monitor network traffic and system logs for suspicious activity, including unusual login attempts or data exfiltration, to detect potential ransomware attacks early. * Educate users on phishing scams and social engineering tactics used by attackers like JadePuffer, and provide training on how to identify and report suspicious emails or messages. * Use secure coding practices when developing applications that interact with Internet-facing systems, such as using HTTPS encryption for data transmission and validating user input before processing it.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ca•••••.lnk
ap•••••.groq
cr•••••.json
CA•••••.pdf
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-3248CVE-2025-3248 CVE-2021-29441CVE-2021-29441
Target & Sectors
LA
Incident Timeline
‎March 11, 2026
The JadePuffer malware was uploaded to the VirusTotal platform on March 11, 2026.
organisation VirusTotal
‎2026/07/06
JadePuffer exploited CVE-2025-3248, an unauthenticated remote code execution vulnerability affecting Langflow.
organisation extorsión de principio
organisation Un
organisation el equipo de investigación de amenazas de Sysdig
organisation Según los investigadores
organisation sino de un
organisation corregir
organisation EU
organisation AI-Driven Ransomware Was Inevitable Indeed
organisation JADEPUFFER
organisation The First Complete LLM-Driven Ransomware Attack
organisation LLM
organisation Interpol
organisation PromptLock
organisation New York University's
organisation Tandon School of Engineering
organisation Ransomware
organisation CrownX.
organisation New Avalon
organisation CVE-2025-3248
organisation CVE-2025
organisation API
organisation una operación bautizada como
organisation la cadena de ataque
organisation el cifrado
organisation la destrucción de una base de datos
organisation ATA
organisation También
organisation El agente
organisation Movimiento
organisation Una de las características
organisation fue la capacidad de corregir
organisation Cuando una consulta
organisation el resultado
organisation un agente de IA
organisation base de
organisation arquitecturas de microservicios
organisation el uso prolongado de
organisation JWT
organisation Cifrado
organisation Los investigadores observaron
organisation denominada README_RANSOM
organisation nota de rescate
organisation Sin
organisation Esto
organisation el rescate
organisation El propio
organisation Cuando uno de los
organisation el borrado
organisation Sysdig
organisation Threat Research Team
organisation Langflow
organisation Postgres
organisation Langlow
organisation Naming and Configuration Service
organisation Detectify
organisation Nacos
organisation AES
organisation IP
organisation Microsoft Defender
organisation SentinelOne
organisation CrowdStrike
organisation Sophos
organisation Elastic Endpoint
organisation FortiEDR
organisation ESET
organisation Avalon
infrastructure Windows
organisation ISO
organisation Windows Shortcut
organisation Event Tracing for
organisation ETW
organisation Gather
organisation Phantom
organisation Discord
organisation Slack, Teams
organisation WireGuard
organisation Chromium
organisation Mozilla Firefox
organisation Collect
organisation SSH
organisation RDP
organisation Telegram
organisation Palo Alto Networks Unit
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources