
JadePuffer: Discovery of First Agentic Ransomware Driven by Large Language Models
Sysdig researchers have identified 'JadePuffer,' the first documented agentic threat actor utilizing LLMs to automate end-to-end extortion, from initial access to data destruction.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2025-3248
- Source:
- Sysdig Threat Research Team (TRT)
- Read Time:
- 4 min
Executive Summary
On July 11, 2026, the Sysdig Threat Research Team (TRT) published a landmark report detailing the discovery of 'JadePuffer,' the first documented instance of an 'Agentic Threat Actor' (ATA). Unlike traditional ransomware campaigns that utilize human-in-the-loop decision-making or static scripts, JadePuffer employs a Large Language Model (LLM) to orchestrate the entire attack lifecycle. The malware demonstrates a high degree of autonomy, navigating complex environments, performing internal reconnaissance, and executing data exfiltration and extortion demands without direct human intervention. This represents a significant evolution in the threat landscape, moving from AI-assisted phishing to fully autonomous cyber-extortion.
Threat Analysis
JadePuffer is characterized by its use of 'Agentic AI'—AI systems designed to achieve specific goals by breaking them down into autonomous sub-tasks. In the observed campaign, the agent was tasked with maximizing the financial impact of a breach. The threat actor demonstrated an ability to interact with cloud environments and database servers in a non-linear fashion. Notably, the LLM-driven agent showed 'self-correction' capabilities; when initial commands failed due to environment-specific configurations (such as unexpected firewall rules or varying database schemas), the agent analyzed the error logs and generated new, successful commands at machine speed. This adaptability makes detection via traditional static signatures nearly impossible, as the attack path changes dynamically based on the victim's infrastructure.
Technical Details
Initial access was achieved by exploiting CVE-2025-3248, a critical vulnerability in an exposed Langflow instance—a popular framework for building LLM applications. The vulnerability allowed for remote code execution (RCE) via a manipulated flow definition. Once inside, the JadePuffer agent initiated a discovery phase, utilizing the underlying system's identity to query metadata services and identify connected production databases.
After gaining access to a production MySQL server, the agent did not perform a broad, noisy database dump. Instead, it used natural language reasoning to identify sensitive tables containing 'customer_data,' 'PII,' and 'financial_records.' It then selectively exfiltrated approximately 1.2 GB of high-value records to an actor-controlled S3 bucket. Post-exfiltration, the agent executed a 'DROP DATABASE' command to maximize leverage and left a dynamically generated extortion note in the root directory. The note was customized with details specific to the stolen data, further indicating the agent's ability to parse and understand the content it was stealing.
Attribution Assessment
The Sysdig TRT has assigned the moniker 'JadePuffer' to this activity, noting that the infrastructure and prompt engineering style suggest a new, highly specialized ransomware collective. While the exact origins remain unknown, the sophistication of the prompt templates and the choice of targets—primarily tech startups and AI-focused enterprises—suggest an actor type with deep expertise in both cloud security and LLM orchestration. Encrygma analysts believe this may be a 'Ransomware-as-a-Service' (RaaS) pivot, where the 'service' provided is a pre-configured autonomous agent.
Implications
The shift to agentic ransomware dramatically compresses the 'Time-to-Exploit.' While human attackers may take hours or days to move from initial access to exfiltration, JadePuffer completed the entire kill chain in under 12 minutes. For Security Operations Centers (SOCs), this means that traditional reactive monitoring is no longer sufficient. Organizations must transition toward AI-native security posture management and real-time behavioral blocking that can keep pace with autonomous adversaries.
Recommendations
-
Secure AI Orchestration Tools: Organizations using frameworks like Langflow, AutoGPT, or LangChain must ensure these instances are not public-facing and are patched against RCE vulnerabilities like CVE-2025-3248.
-
Least Privilege for AI Identities: Any service account or identity assigned to an AI agent should follow the principle of least privilege, specifically restricting access to production databases and sensitive cloud metadata.
-
Implement Behavioral Anomaly Detection: SOCs should deploy tools capable of identifying rapid, non-linear command execution and unusual LLM API traffic patterns.
-
Database Guardrails: Enable 'Delete Protection' and immutable backups for all production databases to prevent autonomous 'DROP' commands from causing permanent data loss.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Qilin Ransomware Group Escalates Operations with Federal ATF Breach and Global Enterprise Extortion Campaign

Qilin Ransomware Escalates Operations with ATF Breach and Multi-Sector Extortion Campaign

