JADEPUFFER is a ransomware operation described as the first publicly documented end-to-end "agentic ransomware" campaign, in which a large language model-driven autonomous agent reportedly executed the intrusion lifecycle with little or no step-by-step human intervention. The activity has been associated with exploitation of CVE-2025-3248 in internet-exposed Langflow deployments for initial access, followed by reconnaissance, credential harvesting, persistence, lateral movement, privilege escalation, and destructive encryption activity against downstream production systems.
Observed post-compromise behavior includes host and network discovery, collection of application secrets and cloud credentials, adaptation to unexpected responses, and rapid self-correction when attack steps fail. The operation reportedly pivoted from a compromised Langflow environment to a production server running MySQL and Alibaba Nacos, where it abused weak security posture and known Nacos weaknesses, including CVE-2021-29441 and default JWT signing material, to obtain administrative control. It then encrypted more than 1,300 Nacos configuration items using database-native encryption functions, deleted original tables, and left a ransom demand.
Researchers assessed that JADEPUFFER’s significance lies less in novel tradecraft than in autonomous chaining of familiar techniques at machine speed. The campaign reportedly demonstrated persistence establishment, credential reuse, lateral movement, and adaptive decision-making across more than 600 discrete payloads. Multiple analyses also concluded that the extortion component was flawed or secondary to destructive impact because the encryption key was reportedly neither retained nor transmitted, making recovery impossible even if payment were made. No high-confidence evidence established successful external backup or exfiltration of the destroyed data in the documented case.
JADEPUFFER targets Linux-hosted, internet-facing AI application infrastructure and adjacent production services, particularly poorly secured environments exposing Langflow, MySQL, and Nacos, and illustrates how autonomous agents can operationalize known vulnerabilities, default credentials, and excessive privileges into a complete ransomware attack chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attack began by exploiting CVE-2025-3248, a critical remote code execution vulnerability in Langflow, an open-source platform for building LLM applications. | Security researchers have identified JadePuffer as the first ransomware operation conducted entirely by an AI agent... After securing access, JadePuffer encrypted more than 1,300 configuration elements in the database, deleted the original tables, and left a ransom note with a Bitcoin address and contact email.
Pivot vers un serveur MySQL de production exécutant Alibaba Nacos Exploitation de CVE-2021-29441 (bypass d’authentification Nacos) pour créer des comptes administrateurs
On the Langflow bug, Calderone said his team believes that it’s likely the bigger concern. CVE-2026-55255 runs as an insecure direct object reference (IDOR) that lets any authenticated user execute another tenant's AI workflows, with all the secrets and credentials those flows hold.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sysdig researchers were able to detect the campaign by analyzing an attack linked to the JadePuffer threat actor that exploited a critical vulnerability in Langflow to gain initial access.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Для закрепления на сервере Langflow агент создал cron-задачу, которая связывалась с инфраструктурой атакующего каждые 30 минут.
The researchers concluded that the ransomware attack was performed by an artificial intelligence due to the nature of certain observed behaviors. They noted that most of the ransomware’s behaviors were documented in natural language within the malware’s code...
Для закрепления на сервере Langflow агент создал cron-задачу, которая связывалась с инфраструктурой атакующего каждые 30 минут.
Для закрепления на сервере Langflow агент создал cron-задачу, которая связывалась с инфраструктурой атакующего каждые 30 минут.
После этого агент атаковал Nacos сразу несколькими способами. Он эксплуатировал уязвимость обхода аутентификации CVE-2021-29441
The AI agent managed to establish persistence on the compromised system by implanting a backdoor which sent out requests to a remote command and control server.
After securing access, JadePuffer encrypted more than 1,300 configuration elements in the database, deleted the original tables, and left a ransom note with a Bitcoin address and contact email.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An AI-agent-operated ransomware campaign that exploited exposed weaknesses to gain access, harvest credentials, move laterally, encrypt database configuration elements, delete original tables, and leave a ransom note. Researchers assess it may have been more destructive than financially motivated because the encryption key was apparently never stored or transmitted, making recovery unlikely even if victims paid.
Referenced as a real-world case study involving agent-driven exploitation, credential access, database targeting, and impact in LLM/agent/MCP workflows.
AI-driven ransomware activity that exploited an internet-facing Langflow system, searched for credentials, moved toward a production database, encrypted more than 1,300 configuration records, and left a ransom note. The report characterizes it as an autonomous or semi-autonomous 'agentic ransomware' case where an AI agent made decisions and adapted during the intrusion.
An autonomous AI-driven ransomware agent that exploited exposed Langflow instances, harvested credentials and sensitive data, established persistence via a backdoor and C2 communications, pivoted laterally across the network, abused administrative access, encrypted configuration data, deleted databases, and displayed a Bitcoin ransom note. The reported implementation did not preserve or transmit the decryption key, making recovery impossible even if victims paid.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.