INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
JadePuffer: First Complete LLM-Driven Ransomware Attack
| 2026-07-06 12:23 CRITICAL LOW AI-ENABLED ATTACK · AUTONOMOUS RANSOMWARE & EXTORTION
Executive Summary
AI-generated
Researchers at Sysdig have discovered a campaign run by an "agentic threat actor" known as JadePuffer, which exploited a flaw in an Internet-facing Langflow deployment and then pivoted to a production database server to execute an adaptive and fully automated ransomware campaign. The attack was carried out autonomously using a large language model (LLM) agent that can chain reconnaissance, credential theft, lateral movement, persistence, and destruction without human operator intervention. This marks the first documented case of an end-to-end ransomware operation executed by a large language model, ushering in a new era in cyberattacks expected by security experts for years.
Technical Mitigations AI-generated
* Implement robust security measures to prevent exploitation of known vulnerabilities, such as regular software updates and patching, to reduce the attack surface.
* Use multi-factor authentication (MFA) for all sensitive systems and services to increase the difficulty of unauthorized access.
* Regularly monitor network traffic and system logs for suspicious activity, including unusual login attempts or data exfiltration, to detect potential ransomware attacks early.
* Educate users on phishing scams and social engineering tactics used by attackers like JadePuffer, and provide training on how to identify and report suspicious emails or messages.
* Use secure coding practices when developing applications that interact with Internet-facing systems, such as using HTTPS encryption for data transmission and validating user input before processing it.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ca•••••.lnk
ap•••••.groq
cr•••••.json
CA•••••.pdf
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-3248CVE-2025-3248
CVE-2021-29441CVE-2021-29441
Target & Sectors
LA
Incident Timeline
March 11, 2026
The JadePuffer malware was uploaded to the VirusTotal platform on March 11, 2026.
Click on any entity below to view its context and source!
organisation
VirusTotal
The artifact was
uploaded
to the VirusTotal platform on March 11, 2026, and has zero detections across all engines to date.
2026/07/06
JadePuffer exploited CVE-2025-3248, an unauthenticated remote code execution vulnerability affecting Langflow.
Click on any entity below to view its context and source!
organisation
extorsión de principio
JADEPUFFER, el primer ransomware agéntico capaz de ejecutar una extorsión de principio a fin.
organisation
Un
Un nuevo caso
documentado
por el equipo de investigación de amenazas de Sysdig apunta a un cambio relevante en la evolución del ransomware.
organisation
el equipo de investigación de amenazas de Sysdig
Un nuevo caso
documentado
por el equipo de investigación de amenazas de Sysdig apunta a un cambio relevante en la evolución del ransomware.
organisation
Según los investigadores
Según los investigadores, se trataría del primer caso conocido de ransomware agéntico, es decir, una campaña en la que la capacidad operativa no depende de un atacante tomando decisiones manualmente, sino de un agente de inteligencia artificial capaz de reconocer el entorno, corregir errores y adaptar sus acciones en tiempo real.
organisation
sino de un
Según los investigadores, se trataría del primer caso conocido de ransomware agéntico, es decir, una campaña en la que la capacidad operativa no depende de un atacante tomando decisiones manualmente, sino de un agente de inteligencia artificial capaz de reconocer el entorno, corregir errores y adaptar sus acciones en tiempo real.
organisation
corregir
Según los investigadores, se trataría del primer caso conocido de ransomware agéntico, es decir, una campaña en la que la capacidad operativa no depende de un atacante tomando decisiones manualmente, sino de un agente de inteligencia artificial capaz de reconocer el entorno, corregir errores y adaptar sus acciones en tiempo real.
organisation
EU
Phishers Gain Persistence at EU, Asia Hospitality Orgs
AI-Driven Ransomware Was Inevitable
Indeed, JadePuffer demonstrates how
AI agents
are evolving from productivity tools into autonomous offensive capabilities, representing a paradigm shift in how extortion-based attacks are carried out, according to Clark.
organisation
AI-Driven Ransomware Was Inevitable
Indeed
Phishers Gain Persistence at EU, Asia Hospitality Orgs
AI-Driven Ransomware Was Inevitable
Indeed, JadePuffer demonstrates how
AI agents
are evolving from productivity tools into autonomous offensive capabilities, representing a paradigm shift in how extortion-based attacks are carried out, according to Clark.
organisation
JADEPUFFER
JadePuffer: The First Complete LLM-Driven Ransomware Attack.
Researchers Claim First Fully Agentic Ransomware: JadePuffer.
Tras obtener acceso, JADEPUFFER realizó un reconocimiento completo del sistema.
The agentic threat actor (ATA) behind the operation has been codenamed JADEPUFFER.
organisation
The First Complete LLM-Driven Ransomware Attack
JadePuffer: The First Complete LLM-Driven Ransomware Attack.
organisation
LLM
The first documented case of an end-to-end
ransomware operation
executed autonomously by a large language model (LLM) has successfully performed extortion without a human operator, ushering in a new era in cyberattacks that has long been expected by security experts.
Langflow access via vulnerability exploitation
Reconnaissance and credential harvesting (LLM APIs, cloud credentials, database credentials etc)
Local data theft including Langflow's own backing Postgres database
Lateral discovery for services reachable from the Langflow host
MinIO object-store enumeration and credential harvest
Creation of cron job on the Langlow server for persistence
Access to a production MySQL server running Alibaba Nacos (Naming and Configuration Service), using root credentials
Targeting of Nacos with various payloads including exploitation of CVE-2021-29441
Mass data destruction appears to have been the aim.
"This work introduces an LLM translation layer that replaces shell syntax with plain text.
organisation
Interpol
Related:
Ransomware Thugs Masquerade as Interpol to Entice Small Biz
During the attack, the machine compromised during initial access was used in the compromise of the final target, with all payloads delivered as Base64-encoded Python through the Langflow RCE endpoint.
organisation
PromptLock
In fact, last August, security researchers believed they discovered the first AI-driven ransomware,
called PromptLock,
outside of an attack scenario.
organisation
New York University's
The ransomware was later found to be a proof of concept developed by researchers at New York University's Tandon School of Engineering.
organisation
Tandon School of Engineering
The ransomware was later found to be a proof of concept developed by researchers at New York University's Tandon School of Engineering.
organisation
Ransomware
Four Key Takeaways
Sysdig
claimed
its JadePuffer discovery highlights four things:
Ransomware can be carried out by
LLM agents rather than skilled threat actors.
organisation
CrownX.
The ransomware component has been internally named CrownX.
"The attack began with a spoofed legal document email directing recipients to a password protected archive on Proton Drive," Blackpoint Cyber researchers Nevan Beal and Sam Decker
said
.
organisation
New Avalon
New Avalon Malware Framework Packs CrownX Ransomware Capabilities.
organisation
CVE-2025-3248
El
incidente
comenzó con la explotación de una instancia de Langflow expuesta a internet mediante CVE-2025-3248, una vulnerabilidad que permite ejecutar código Python sin autenticación.
Other recommendations for organizations in the wake of the attack include patching Langflow to a release that fixes CVE-2025-3248 and ensuring code-execution/validation endpoints are not exposed to the Internet; avoiding linking provider API keys or cloud credentials to their associated AI-orchestration server environment; and hardening Nacos.
The operator "gained initial access to an internet-facing Langflow instance through CVE-2025-3248 and ran an adaptive and fully automated campaign, ultimately pivoting to the intended target and running a destructive database-extortion playbook against the victim's production database server," Sysdig's Michael Clark said.
organisation
CVE-2025
First, JadePuffer exploited
CVE-2025-3248
, an unauthenticated remote code execution (RCE) vulnerability affecting Langflow, which is an open source tool for building AI applications.
organisation
API
Other recommendations for organizations in the wake of the attack include patching Langflow to a release that fixes CVE-2025-3248 and ensuring code-execution/validation endpoints are not exposed to the Internet; avoiding linking provider API keys or cloud credentials to their associated AI-orchestration server environment; and hardening Nacos.
Once launched, the implant transmits basic details about the compromised system to the attacker's Telegram bot and enters into a command-and-control (C2) loop that polls the bot API every 5 seconds for new messages.
organisation
una operación bautizada como
La compañía ha identificado una operación bautizada como JADEPUFFER en la que un modelo de lenguaje habría dirigido de forma autónoma toda la cadena de ataque, desde el acceso inicial hasta el cifrado y la destrucción de una base de datos.
organisation
la cadena de ataque
La compañía ha identificado una operación bautizada como JADEPUFFER en la que un modelo de lenguaje habría dirigido de forma autónoma toda la cadena de ataque, desde el acceso inicial hasta el cifrado y la destrucción de una base de datos.
organisation
el cifrado
La compañía ha identificado una operación bautizada como JADEPUFFER en la que un modelo de lenguaje habría dirigido de forma autónoma toda la cadena de ataque, desde el acceso inicial hasta el cifrado y la destrucción de una base de datos.
organisation
la destrucción de una base de datos
La compañía ha identificado una operación bautizada como JADEPUFFER en la que un modelo de lenguaje habría dirigido de forma autónoma toda la cadena de ataque, desde el acceso inicial hasta el cifrado y la destrucción de una base de datos.
organisation
ATA
The agentic threat actor (ATA) behind the operation has been codenamed JADEPUFFER.
organisation
También
También trató de localizar credenciales de AWS, Azure, Google Cloud y varios proveedores chinos, además de monederos de criptomonedas, frases semilla y datos de acceso a bases de datos.
organisation
El agente
El agente extrajo información de la base de datos PostgreSQL utilizada por Langflow, revisó los archivos obtenidos y eliminó después los elementos temporales.
organisation
Movimiento
Movimiento lateral y robo de credenciales
La campaña no se limitó al servidor comprometido inicialmente.
organisation
Una de las características
Una de las características más llamativas fue la capacidad de corregir errores.
organisation
fue la capacidad de corregir
Una de las características más llamativas fue la capacidad de corregir errores.
organisation
Cuando una consulta
Cuando una consulta devolvió información en formato XML en lugar de JSON, el sistema modificó inmediatamente su analizador y repitió la petición.
organisation
el resultado
Este comportamiento, basado en observar el resultado y adaptar el siguiente paso, es uno de los indicios que llevaron a Sysdig a considerar que la campaña estaba siendo dirigida por un agente de IA.
organisation
un agente de IA
Este comportamiento, basado en observar el resultado y adaptar el siguiente paso, es uno de los indicios que llevaron a Sysdig a considerar que la campaña estaba siendo dirigida por un agente de IA.
organisation
base de
El verdadero objetivo era una base de datos de producción
El servidor Langflow actuó como punto de entrada, pero el objetivo final era otro sistema expuesto a internet que ejecutaba una base de datos MySQL y un servicio de configuración Nacos.
organisation
arquitecturas de microservicios
Nacos es una plataforma utilizada en arquitecturas de microservicios y cuenta con un historial de vulnerabilidades y configuraciones inseguras.
organisation
el uso prolongado de
Entre ellas se encuentran fallos de autenticación y el uso prolongado de claves JWT predeterminadas.
organisation
JWT
Entre ellas se encuentran fallos de autenticación y el uso prolongado de claves JWT predeterminadas.
organisation
Cifrado
Cifrado, destrucción y extorsión
Una vez dentro, el agente ejecutó una campaña destructiva.
organisation
Los investigadores observaron
Los investigadores observaron cómo cifraba 1.342 elementos de configuración almacenados en Nacos mediante la función AES_ENCRYPT de MySQL.
organisation
denominada README_RANSOM
Después eliminó las tablas originales y creó una tabla denominada README_RANSOM con una nota de rescate, una dirección de Bitcoin y un contacto de Proton Mail.
organisation
nota de rescate
Después eliminó las tablas originales y creó una tabla denominada README_RANSOM con una nota de rescate, una dirección de Bitcoin y un contacto de Proton Mail.
organisation
Sin
Sin embargo, la clave de cifrado se generó de forma aleatoria, se mostró una única vez
organisation
Esto
Esto implica que la información no podría recuperarse incluso aunque la víctima pagara el rescate.
organisation
el rescate
Esto implica que la información no podría recuperarse incluso aunque la víctima pagara el rescate.
organisation
El propio
El propio código incluía comentarios en lenguaje natural sobre qué sistemas ofrecían un mayor retorno para el atacante y cuáles debían ser eliminados primero.
organisation
Cuando uno de los
Cuando uno de los comandos falló por una restricción de claves foráneas, JADEPUFFER desactivó temporalmente la comprobación de integridad, repitió el borrado y volvió a activar la protección.
organisation
el borrado
Cuando uno de los comandos falló por una restricción de claves foráneas, JADEPUFFER desactivó temporalmente la comprobación de integridad, repitió el borrado y volvió a activar la protección.
organisation
Sysdig
It then ran “an adaptive and fully automated campaign” which resulted in “a destructive database-extortion playbook against the victim's production database server,” according to Sysdig's Threat Research Team.
The most striking aspect was that "JadePuffer's own payloads were self-narrating," Michael Clark, Sysdig's director of threat research, wrote in the report.
organisation
Threat Research Team
It then ran “an adaptive and fully automated campaign” which resulted in “a destructive database-extortion playbook against the victim's production database server,” according to Sysdig's Threat Research Team.
organisation
Langflow
Langflow access via vulnerability exploitation
Reconnaissance and credential harvesting (LLM APIs, cloud credentials, database credentials etc)
Local data theft including Langflow's own backing Postgres database
Lateral discovery for services reachable from the Langflow host
MinIO object-store enumeration and credential harvest
Creation of cron job on the Langlow server for persistence
Access to a production MySQL server running Alibaba Nacos (Naming and Configuration Service), using root credentials
Targeting of Nacos with various payloads including exploitation of CVE-2021-29441
Mass data destruction appears to have been the aim.
organisation
Postgres
Langflow access via vulnerability exploitation
Reconnaissance and credential harvesting (LLM APIs, cloud credentials, database credentials etc)
Local data theft including Langflow's own backing Postgres database
Lateral discovery for services reachable from the Langflow host
MinIO object-store enumeration and credential harvest
Creation of cron job on the Langlow server for persistence
Access to a production MySQL server running Alibaba Nacos (Naming and Configuration Service), using root credentials
Targeting of Nacos with various payloads including exploitation of CVE-2021-29441
Mass data destruction appears to have been the aim.
organisation
Langlow
Langflow access via vulnerability exploitation
Reconnaissance and credential harvesting (LLM APIs, cloud credentials, database credentials etc)
Local data theft including Langflow's own backing Postgres database
Lateral discovery for services reachable from the Langflow host
MinIO object-store enumeration and credential harvest
Creation of cron job on the Langlow server for persistence
Access to a production MySQL server running Alibaba Nacos (Naming and Configuration Service), using root credentials
Targeting of Nacos with various payloads including exploitation of CVE-2021-29441
Mass data destruction appears to have been the aim.
organisation
Naming and Configuration Service
Langflow access via vulnerability exploitation
Reconnaissance and credential harvesting (LLM APIs, cloud credentials, database credentials etc)
Local data theft including Langflow's own backing Postgres database
Lateral discovery for services reachable from the Langflow host
MinIO object-store enumeration and credential harvest
Creation of cron job on the Langlow server for persistence
Access to a production MySQL server running Alibaba Nacos (Naming and Configuration Service), using root credentials
Targeting of Nacos with various payloads including exploitation of CVE-2021-29441
Mass data destruction appears to have been the aim.
organisation
Detectify
JadePuffer Unsophisticated, Yet Adaptable
None of JadePuffer's specific attack techniques were novel or sophisticated, says Johan Edholm, co-founder of Detectify, who calls the attack "more evolution than invention."
organisation
Nacos
The JadePuffer attackers encrypted all 1342 Nacos service configuration items and deleted the originals.
organisation
AES
“Critically, the AES key was generated as base64(uuid4().bytes + uuid4().bytes), which is essentially random, and printed to stdout but never persisted or transmitted.
organisation
IP
The IP address, 64.20.53[.]230, only appears here with no evidence that anything was backed up to it.”
organisation
Microsoft Defender
The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender.
organisation
SentinelOne
The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender.
organisation
CrowdStrike
The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender.
organisation
Sophos
The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender.
organisation
Elastic Endpoint
The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender.
organisation
FortiEDR
The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender.
organisation
ESET
The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender.
organisation
Avalon
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed
Avalon
that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls.
infrastructure
Windows
"Malicious content was embedded inside an ISO image rather than attached directly, reducing the likelihood of detection at the email layer."
Should the email recipient interact with a document-themed Windows Shortcut ("Secure Document CA-283505.pdf.lnk") inside the mounted image, it triggers a staged malware sequence that culminates in the deployment of Avalon.
The MSBuild project, for its part, loads an embedded .NET assembly, which then interferes with the regular functioning of Event Tracing for Windows (ETW) to reduce forensic visibility and download a next-stage payload over HTTPS responsible for launching Avalon.
Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic Wallet, Ledger Live, and Bitcoin Core, along with Discord, Slack, Teams, OpenVPN, WireGuard, and Windows Credential Manager.
Encrypt files associated with business operations, software development, engineering, data storage, and virtual infrastructure using Windows
Cryptography API
and deliver a ransom note containing payment instructions and deadline timers that show how much time is left before the ransom amount is increased.
organisation
ISO
"Malicious content was embedded inside an ISO image rather than attached directly, reducing the likelihood of detection at the email layer."
Should the email recipient interact with a document-themed Windows Shortcut ("Secure Document CA-283505.pdf.lnk") inside the mounted image, it triggers a staged malware sequence that culminates in the deployment of Avalon.
organisation
Windows Shortcut
"Malicious content was embedded inside an ISO image rather than attached directly, reducing the likelihood of detection at the email layer."
Should the email recipient interact with a document-themed Windows Shortcut ("Secure Document CA-283505.pdf.lnk") inside the mounted image, it triggers a staged malware sequence that culminates in the deployment of Avalon.
organisation
Event Tracing for
The MSBuild project, for its part, loads an embedded .NET assembly, which then interferes with the regular functioning of Event Tracing for Windows (ETW) to reduce forensic visibility and download a next-stage payload over HTTPS responsible for launching Avalon.
organisation
ETW
The MSBuild project, for its part, loads an embedded .NET assembly, which then interferes with the regular functioning of Event Tracing for Windows (ETW) to reduce forensic visibility and download a next-stage payload over HTTPS responsible for launching Avalon.
organisation
Gather
Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic Wallet, Ledger Live, and Bitcoin Core, along with Discord, Slack, Teams, OpenVPN, WireGuard, and Windows Credential Manager.
organisation
Phantom
Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic Wallet, Ledger Live, and Bitcoin Core, along with Discord, Slack, Teams, OpenVPN, WireGuard, and Windows Credential Manager.
organisation
Discord
Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic Wallet, Ledger Live, and Bitcoin Core, along with Discord, Slack, Teams, OpenVPN, WireGuard, and Windows Credential Manager.
organisation
Slack, Teams
Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic Wallet, Ledger Live, and Bitcoin Core, along with Discord, Slack, Teams, OpenVPN, WireGuard, and Windows Credential Manager.
organisation
WireGuard
Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic Wallet, Ledger Live, and Bitcoin Core, along with Discord, Slack, Teams, OpenVPN, WireGuard, and Windows Credential Manager.
organisation
Chromium
The complete set of features built into Avalon is as follows -
Harvest credentials, cookies, history, and bookmarks from Chromium-based browsers and Mozilla Firefox.
organisation
Mozilla Firefox
The complete set of features built into Avalon is as follows -
Harvest credentials, cookies, history, and bookmarks from Chromium-based browsers and Mozilla Firefox.
organisation
Collect
Collect details about SSH known hosts, saved RDP connections, Wi-Fi profiles, and Group Policy Preferences cpassword artifacts.
organisation
SSH
Collect details about SSH known hosts, saved RDP connections, Wi-Fi profiles, and Group Policy Preferences cpassword artifacts.
organisation
RDP
Collect details about SSH known hosts, saved RDP connections, Wi-Fi profiles, and Group Policy Preferences cpassword artifacts.
organisation
Telegram
The attacker types plaintext instructions in Telegram," Palo Alto Networks Unit 42
said
.
organisation
Palo Alto Networks Unit
The attacker types plaintext instructions in Telegram," Palo Alto Networks Unit 42
said
.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
…tly, reducing the likelihood of detection at the email layer."
Should the email recipient interact with a document-themed Windows Shortcut ("Secure Document CA-283505.pdf.lnk") inside the mounted image, it triggers a staged malware sequence that…
…oject, for its part, loads an embedded .NET assembly, which then interferes with the regular functioning of Event Tracing for Windows (ETW) to reduce forensic visibility and download a next-stage payload over HTTPS responsible for launching Avalon.
Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic Wallet, Ledger Live, and Bitcoin Core, along with Discord, Slack, Teams, OpenVPN, WireGuard, and Windows Credential Manager.
…iles associated with business operations, software development, engineering, data storage, and virtual infrastructure using Windows
Cryptography API
and deliver a ransom note containing payment instructions and deadline timers that show how much…
Intelligence Sources
Infosecurity-Magazine
2026-07-06
Researchers Claim First Fully Agentic Ransomware: JadePuffer
Infosecurity-Magazine
The Hacker News
2026-07-03
Bit Life Media
2026-07-06
Dark Reading
2026-07-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-07T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
83x
organisation
Identified Entity
extorsión de principio
entity
7x
tactic
Cyber Operation Type
Ransomware
tactic
6x
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
4x
industry
Targeted Sector
Hospitality
sector
2x
vulnerability
Exploited CVE
CVE-2025-3248
cve
2x
timeline
Temporal Reference
2021
date
Contextual Telemetry
Context Block
6 METRICS
target region
Target Country
Lao People's Democratic Republic
country
general metric
Elementos
1
elementos
general metric
Segundos
31
segundos
infrastructure
Affected Product
Windows
software
general metric
Seconds
5
seconds
general metric
Palo Alto Networks Unit
42
palo alto networks unit
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.