Security researchers at Sysdig say they documented “JadePuffer,” a ransomware campaign carried out end to end by an AI agent using a large language model, without human operators at the keyboard. According to Sysdig, the agent first gains initial access by exploiting a remote-code-execution vulnerability in the Langflow open-source framework; that flaw has since been patched. After exploitation, the agent runs an adaptive, fully automated intrusion workflow, including retrying failed actions with refined parameters. Sysdig’s researchers describe behavior such as going from a failed login to a working fix in about 31 seconds, harvesting and reusing credentials, moving laterally, establishing persistence, and targeting a victim’s production database for extortion and destruction. The research also says the agent encrypted data using an ephemeral, unrecoverable AES key, making decryption impossible even if a victim pays. Multiple outlets report that JadePuffer injects persistence on the initially compromised host and ultimately destroys data in the targeted environment. Overall, researchers warn that such agentic tooling could reduce the cost and expertise required to run ransomware, potentially increasing the volume and breadth of similar attacks as the technology matures.
Sysdig reports JadePuffer: an AI agent performs end-to-end ransomware attack
Security researchers at Sysdig say they documented “JadePuffer,” a ransomware campaign carried out end to end by an AI agent using a large language model, without human operators at the keyboard. Acco...
- Sysdig reports a ransomware campaign, dubbed JadePuffer, executed end to end by an LLM-based AI agent without human intervention.
- The initial access vector involves exploiting a Langflow remote code execution vulnerability (since patched).
- Researchers say the agent adapts in real time, retrying failed steps and progressing autonomously through the attack chain.
- The campaign includes actions such as credential harvesting/reuse, lateral movement, establishing persistence, and compromising a production database.
- Sysdig says the ransomware uses an ephemeral, unrecoverable encryption key, leaving encrypted configurations unrecoverable even if ransom is paid.
How a broken login got fixed in 31 seconds, and what that actually meansContinue reading on AI-Nauts »
1 month agoTypically, when hackers attempt to break into a system, they have to retrace steps and make incremental changes time and again. A new campaign called JadePuffer, run entirely by AI, instead works autonomously, finding unexplored avenues on its own to continuously deploy brute-force tactics. It could increase the spread of the incursion exponentially. A recent report from cloud security firm Sysdig details the capabilities of JadePuffer, which it says is the first ransomware campaign run completely by a large language model (LLM). And it could mark the beginning of a new era in online crime. The agent “adapted in real time, retrying failed steps within refined parameters,” wrote Michael Clark, Sysdig’s senior director of threat research, in a memo. “In one sequence, it went from a failed login to a working fix in 31 seconds.” The observed attack involved a vulnerability in the Langflow open-source framework, which is used to build LLM applications. (The vulnerability has since been patched.) Once it exploited that vulnerability, it ran “an adaptive and fully automated campaign” that resulted in “a destructive database-extortion playbook against the victim’s production database server,” Sysdig’s report reads. For potential targets, that raises the stakes. As these threats become more common, businesses (and people) who are targeted will need to respond a lot faster to attacks, Sysdig emphasized in its report. “JadePuffer is a warning sign,” Clark wrote. “It’s a marker of where extortion tradecraft is heading. An autonomous agent reasoned about its targets, harvested and reused credentials, moved laterally, established persistence, and destroyed a database, narrating its own intent the entire way.” The techniques the campaign used were neither novel nor sophisticated. What made this worrisome was the way the AI model brought them all together, on its own, to create the ransomware operation. That lowers the cost of operating a hacking group to the cost of running an agent—and makes it easier for would-be hackers who aren’t as skilled at programming to launch attacks. Possibly even worse is the scenario in which hackers steal credentials to run an agent, taking their costs to virtually nothing. And now that one LLM-driven ransomware agent has been spotted in the wild, expect others, the security firm warned. “Defenders should expect the volume and breadth of such campaigns to rise as agentic tooling matures, and they should treat exposed application servers, unhardened configuration stores, and internet-facing database admin accounts as the first surfaces that will be attacked,” Sysdic wrote. While any ransomware attack can be catastrophic for the victim, JadePuffer also introduced a new, nihilistic threat. Generally, if a business is attacked and pays the ransom, it’s once again able to access its data. But with JadePuffer, the company is out of luck, whether it pays the ransom or not. “The AES [Advanced Encryption Standard] key was ephemeral and unrecoverable, so the victim’s configurations are unrecoverable, even with payment,” Sysdig wrote. This new milestone comes as ransomware continues to be a preferred method of hackers. Cybercriminals pocketed more than $32 million from ransomware attacks last year—and the totals get significantly higher when you factor in business disruptions, equipment, and third-party remediation costs. (They climb even more when you consider that the majority of ransomware attacks go unreported.) The number of reported ransomware attacks hit a record 9,251 cases in 2025, a 45% increase from 2024, according to data collected by the threat exposure management platform NordStellar. AI firms have warned these sorts of attacks could be coming. Last August, hackers discovered an exploit in Anthropic’s Claude chatbot that allowed them to “commit large-scale theft and extortion of personal data” at 17 (and perhaps more) organizations in the healthcare, emergency services, government, and religion industries. “This represents an evolution in AI-assisted cybercrime,” Anthropic said in a statement at the time. “AI tools are now being used to provide both technical advice and active operational support for attacks that would otherwise have required a team of operators. … We expect attacks like this to become more common as AI-assisted coding reduces the technical expertise required for cybercrime.”
1 month agoJadePuffer could be the first reported case of a ransomware attack driven by AI from start to finish. How can businesses respond?
1 month agoArtificial intelligence has already changed how we code, automate, and analyze data.Continue reading on Medium »
1 month agoSecurity firm Sysdig says it has documented the first ransomware attack run end to end by an AI agent, first reported by Business Insider. A large language model planned, executed, and adapted the entire operation, which Sysdig has named JadePuffer. The agent chained together every stage of the attack, from reconnaissance and credential theft to lateral […] This story continues at The Next Web
1 month agoResearchers have revealed JadePuffer, the first agentic AI-powered ransomware campaign, highlighting how autonomous agents can automate cyber-attacks
1 month agoMeta goes on trial as 29 US states accuse Facebook and Instagram of harming children
Meta is on trial in federal court in Oakland, with 29 US states accusing the company of designing Facebook and Instagram...
Moonshot AI seeks up to 30% revenue share with Microsoft, Amazon, Google for Kimi K3 hosting
Chinese AI startup Moonshot AI is in early talks with Microsoft, Amazon and Google about hosting its Kimi K3 model on th...
World stocks edge up as oil falls amid Hormuz reopening hopes and upcoming data
World stock markets tick higher as oil prices decline, with sentiment supported by renewed hopes that the Strait of Horm...