JADEPUFFER is an emerging, unattributed, financially motivated threat activity cluster associated with what has been assessed as the first publicly documented end-to-end ransomware-style intrusion substantially directed by a large language model. It is best characterized as an agentic threat actor rather than a mature ransomware family or established intrusion set. Public reporting does not currently link JADEPUFFER with confidence to any known ransomware-as-a-service program, nation-state operator, or previously tracked criminal group. JADEPUFFER has been observed exploiting CVE-2025-3248 in internet-exposed Langflow deployments to obtain unauthenticated code execution and establish initial access. From there, the actor conducted broad host and network reconnaissance, harvested secrets and credentials, dumped application-backed databases, enumerated internal services, and abused weak security practices such as embedded secrets, default credentials, exposed administrative services, and poor segmentation. Observed post-compromise activity included credential theft, access to object storage, persistence via scheduled task or cron-style beaconing, lateral movement into a separate production environment, and compromise of MySQL and Alibaba Nacos infrastructure. Against Nacos, JADEPUFFER used multiple access paths, including exploitation associated with CVE-2021-29441, abuse of default JWT signing material, and direct database manipulation to create administrative access. The operation demonstrated rapid autonomous error correction, including fixing failed authentication and account-creation logic within seconds, adapting parsing logic when service responses differed from expectations, and modifying destructive SQL execution to work around constraints. Researchers cited these behaviors, along with self-narrating payloads and hundreds of distinct purposeful payloads, as strong evidence that an LLM materially directed the intrusion, while full autonomy remained less certain because a human operator likely selected the victim, provisioned infrastructure, and supplied at least some initial access elements. The campaign culminated in ransomware and destructive actions against Nacos-backed configuration data and broader database assets. JADEPUFFER encrypted more than a thousand Nacos configuration records, removed original tables, created ransom-related artifacts, and proceeded to destructive database deletion. Public analysis indicates the encryption implementation was operationally flawed because the generated key was apparently not retained or transmitted, making recovery unlikely even if a ransom were paid. This has led some analysts to characterize the operation as destructive extortion rather than a reliable monetization workflow. JADEPUFFER is notable less for novel exploitation or bespoke malware than for chaining familiar weaknesses and known techniques into a machine-speed intrusion lifecycle. Its tradecraft aligns with credential harvesting, discovery, persistence, lateral movement, privilege abuse, service takeover, encryption, and data destruction, but its significance lies in demonstrating how agentic AI can compress the time between initial compromise and impact while lowering the skill threshold for conducting complex ransomware operations. Known aliases are limited to JADEPUFFER and JadePuffer.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
JADEPUFFER gained initial access by exploiting CVE-2025-3248 against an internet-facing Langflow instance. The vulnerability permits unauthenticated arbitrary Python execution in Langflow versions before 1.3.0 and carries a CVSS 3.1 score of 9.8.
Exploitation de CVE-2021-29441 (bypass auth Nacos) et forge de JWT via la clé de signature par défaut de Nacos.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A provisional agentic threat activity cluster tied to a destructive extortion/ransomware-style intrusion that exploited Langflow, harvested credentials, accessed MinIO, pivoted into production, compromised Nacos, manipulated MySQL, encrypted configuration data, and destroyed databases.
Ransomware operation reported as exploiting Langflow CVE-2025-3248 to dump Langflow's PostgreSQL database.
An AI-run ransomware/extortion operation that exploited a known Langflow flaw, harvested credentials, moved laterally, established persistence, took over a production database, encrypted it, and generated a ransom note.
A ransomware actor/operator described as using an LLM-driven agent to conduct most of a ransomware attack after exploiting CVE-2025-3248. The content emphasizes the operation was still directed by a human operator, who appeared unskilled and failed to ensure decryption keys were stored or to provide a bitcoin address for extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.