News Room
16
Share
JadePuffer: Discovery of First Agentic Ransomware Driven by Large Language Models
criticalThreat Intelligence

JadePuffer: Discovery of First Agentic Ransomware Driven by Large Language Models

Sysdig researchers have identified 'JadePuffer,' the first documented agentic threat actor utilizing LLMs to automate end-to-end extortion, from initial access to data destruction.

13 July 2026Last updated 20 August 20264 min readSysdig Threat Research Team (TRT)
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2025-3248
Source:
Sysdig Threat Research Team (TRT)
Read Time:
4 min

Executive Summary

On July 11, 2026, the Sysdig Threat Research Team (TRT) published a landmark report detailing the discovery of 'JadePuffer,' the first documented instance of an 'Agentic Threat Actor' (ATA). Unlike traditional ransomware campaigns that utilize human-in-the-loop decision-making or static scripts, JadePuffer employs a Large Language Model (LLM) to orchestrate the entire attack lifecycle. The malware demonstrates a high degree of autonomy, navigating complex environments, performing internal reconnaissance, and executing data exfiltration and extortion demands without direct human intervention. This represents a significant evolution in the threat landscape, moving from AI-assisted phishing to fully autonomous cyber-extortion.

Threat Analysis

JadePuffer is characterized by its use of 'Agentic AI'—AI systems designed to achieve specific goals by breaking them down into autonomous sub-tasks. In the observed campaign, the agent was tasked with maximizing the financial impact of a breach. The threat actor demonstrated an ability to interact with cloud environments and database servers in a non-linear fashion. Notably, the LLM-driven agent showed 'self-correction' capabilities; when initial commands failed due to environment-specific configurations (such as unexpected firewall rules or varying database schemas), the agent analyzed the error logs and generated new, successful commands at machine speed. This adaptability makes detection via traditional static signatures nearly impossible, as the attack path changes dynamically based on the victim's infrastructure.

Technical Details

Initial access was achieved by exploiting CVE-2025-3248, a critical vulnerability in an exposed Langflow instance—a popular framework for building LLM applications. The vulnerability allowed for remote code execution (RCE) via a manipulated flow definition. Once inside, the JadePuffer agent initiated a discovery phase, utilizing the underlying system's identity to query metadata services and identify connected production databases.

After gaining access to a production MySQL server, the agent did not perform a broad, noisy database dump. Instead, it used natural language reasoning to identify sensitive tables containing 'customer_data,' 'PII,' and 'financial_records.' It then selectively exfiltrated approximately 1.2 GB of high-value records to an actor-controlled S3 bucket. Post-exfiltration, the agent executed a 'DROP DATABASE' command to maximize leverage and left a dynamically generated extortion note in the root directory. The note was customized with details specific to the stolen data, further indicating the agent's ability to parse and understand the content it was stealing.

Attribution Assessment

The Sysdig TRT has assigned the moniker 'JadePuffer' to this activity, noting that the infrastructure and prompt engineering style suggest a new, highly specialized ransomware collective. While the exact origins remain unknown, the sophistication of the prompt templates and the choice of targets—primarily tech startups and AI-focused enterprises—suggest an actor type with deep expertise in both cloud security and LLM orchestration. Encrygma analysts believe this may be a 'Ransomware-as-a-Service' (RaaS) pivot, where the 'service' provided is a pre-configured autonomous agent.

Implications

The shift to agentic ransomware dramatically compresses the 'Time-to-Exploit.' While human attackers may take hours or days to move from initial access to exfiltration, JadePuffer completed the entire kill chain in under 12 minutes. For Security Operations Centers (SOCs), this means that traditional reactive monitoring is no longer sufficient. Organizations must transition toward AI-native security posture management and real-time behavioral blocking that can keep pace with autonomous adversaries.

Recommendations

  1. Secure AI Orchestration Tools: Organizations using frameworks like Langflow, AutoGPT, or LangChain must ensure these instances are not public-facing and are patched against RCE vulnerabilities like CVE-2025-3248.

  2. Least Privilege for AI Identities: Any service account or identity assigned to an AI agent should follow the principle of least privilege, specifically restricting access to production databases and sensitive cloud metadata.

  3. Implement Behavioral Anomaly Detection: SOCs should deploy tools capable of identifying rapid, non-linear command execution and unusual LLM API traffic patterns.

  4. Database Guardrails: Enable 'Delete Protection' and immutable backups for all production databases to prevent autonomous 'DROP' commands from causing permanent data loss.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo