option
Home
News
JadePuffer: The First Agentic AI Ransomware Emerges

JadePuffer: The First Agentic AI Ransomware Emerges

July 25, 2026
49

Sysdig has documented the first known instance of agentic ransomware, which it has named JadePuffer. Credit: Sysdig

Sysdig reveals that agentic AI ransomware was deployed in a successful attack, while Senior Director of Threat Research Michael Clark warns of what lies ahead.

Researchers have documented the first case of a large language model (LLM) autonomously executing an entire ransomware operation from start to finish.

The Sysdig Threat Research Team has identified what it describes as "a complete extortion operation driven end-to-end by a large language model."

The threat actor, which Sysdig has named JadePuffer, demonstrates how AI systems can now perform complex multi-step technical tasks without human intervention.

The autonomous agent gained access to a victim's database server and executed tasks ranging from reconnaissance to server takeover.

When steps failed, the system corrected itself at machine speed.

Self-narrating autonomous behavior

According to Sysdig, JadePuffer demonstrated reasoning capabilities through natural language processing. The system prioritized its targets and adapted its operation in real time, retrying failed steps using modified parameters.

Behind JadePuffer: The First Agentic AI Ransomware

The researchers documented one instance where the autonomous system moved from a failed login to a working fix in 31 seconds.

The payload included self-narration features that explained its reasoning process, offering a window into how LLMs can now assess technical situations and adjust their strategies dynamically.

Initial access through AI infrastructure

The entry point was CVE-2025-3248, a missing authentication flaw in Langflow.

Langflow is an open-source LLM building framework, and this particular flaw allows attackers to execute Python code on the host.

According to Sysdig, Langflow deployments are often internet-facing and represent attractive targets for bad actors, as servers typically hold API keys and cloud credentials and often lack network controls.

Once the agent gained execution access, it swept the environment, searching for LLM API keys from providers including OpenAI, Anthropic, DeepSeek, and Gemini, along with cloud credentials, cryptocurrency wallets, database credentials, and configuration files.

The skill floor for running ransomware has dropped to whatever it costs to run an agent, and if that agent is running on stolen credentials through LLMjacking, the cost to an attacker is close to zero.

Michael Clark, Senior Director of Threat Research at Sysdig

The system collected cloud credentials and API keys before expanding its access.

It extracted data from Langflow's PostgreSQL database, recovering stored credentials, API keys, and user information before removing temporary files it had created.

Adaptive credential extraction methods

The agent explored the internal network, searching for databases, storage systems, and secret management services.

Eventually, it located a MinIO object storage server where it identified and retrieved more credentials from configuration files.

When its first attempt did not work, the system automatically adapted its approach.

To maintain persistence, the agent installed a scheduled task (cron job) on the compromised Langflow server. The task contacted attacker-controlled infrastructure every 30 minutes.

The autonomous system then pivoted to an internet-facing production server running MySQL and Alibaba Nacos.

Using root MySQL credentials, the agent simultaneously exploited multiple known Nacos authentication weaknesses. The origin of this root credential is unknown.

Real-time error correction capabilities

The system inserted a backdoor administrator account into the platform's database. When its first login attempt failed, it analyzed the error and modified its approach.

According to Sysdig, the agent successfully regained access without human intervention in 31 seconds. This sequence confirms the LLM's ability to perform technical debugging autonomously.

With administrative access established, the system moved to the final stage by encrypting the victim's Nacos configuration data. It replaced the data with a ransom note containing payment instructions.

Michael Clark, Senior Director of Threat Research at Sysdig | Credit: Sysdig (Modified)

Michael Clark, Senior Director of Threat Research at Sysdig, authored the analysis of JadePuffer.

"An autonomous agent reasoned about its targets, harvested and reused credentials, moved laterally, established persistence, and destroyed a database, narrating its own intent the entire way," he says.

Implications for autonomous AI systems

None of the individual techniques were novel or sophisticated, according to Michael. What could be notable is that an AI model connected them into a complete operation against internet-facing infrastructure.

"The skill floor for running ransomware has dropped to whatever it costs to run an agent, and if that agent is running on stolen credentials through LLMjacking, the cost to an attacker is close to zero," he notes.

This could mean the barrier to entry for autonomous AI operations has decreased substantially.

Michael suggests that the volume and breadth of such campaigns could rise as autonomous tooling matures.

The ability of the system to self-narrate throughout the process could provide insight into how autonomous agents make decisions. This transparency feature might be the clue that can help defenders understand the reasoning patterns and ultimately stop attacks by sophisticated AI systems.

Related article
OpenAI Partners with Yubico to Bolster GPT-5.6 Security via Hardware Passkeys OpenAI Partners with Yubico to Bolster GPT-5.6 Security via Hardware Passkeys Jerrod Chong, CEO of Yubico | Image Credit: YubicoOpenAI’s upcoming GPT-5.6 will mandate hardware-backed passkeys starting in September, a move that Yubico CEO Jerrod Chong says confirms their product as the premier defense against account compromise
AI Guardrails Stifle Offensive Cybersecurity Researchers AI Guardrails Stifle Offensive Cybersecurity Researchers For months, AI leaders have implemented strict vetting protocols and safety guardrails to prevent malicious actors from exploiting their models. However, these restrictions are now obstructing legitimate network defenders and offensive cybersecurity
OpenAI Leads 100-Signatory Push for Cyber Defence OpenAI Leads 100-Signatory Push for Cyber Defence OpenAI’s letter begins stating "we have a limited window to strengthen cyber defences". Credit: Getty ImagesMajor tech firms – including AWS, Google and Microsoft – urge governments to fund defensive tools, while critics call the manifesto self-servi
Related Special Topic Recommendations
Image editing AI Object Removal Editors: Clean Up Portraits, Travel, and Product Shots
AI Object Removal Editors: Clean Up Portraits, Travel, and Product Shots

2026 Latest Best Top-rated AI Object Removal Editors for portraits travel product shots! XIX.AI curates a powerful game-changing collection regularly updated with weekly rankings. These tools offer real-world tests to help you quickly remove unwanted elements, boost content quality, and save tons of time without compromising results. Must-try for anyone aiming to unlock their AI creation edge. Explore now!

10 tools
xix.ai
Text-to-speech Best AI Text to Speech Tools for Online Courses
Best AI Text to Speech Tools for Online Courses

2026 Latest Best Top-rated AI Text to Speech Tools for Online Courses are curated by XIX.AI based on rigorous real-world tests and weekly updated rankings. These powerful tools help creators deliver crystal-clear audio content effortlessly, boosting writing efficiency and streamlining course production. Check out the free vs paid comparison to find your perfect fit. Explore now to unlock your AI edge in online education.

10 tools
xix.ai
writing AI Blog Title Tools for Higher Click Through Rates
AI Blog Title Tools for Higher Click Through Rates

2026 Latest Best Top-Rated AI Blog Title Tools for Higher Click Through Rates! XIX.AI has carefully curated a powerful, game-changing collection of top tools that go through rigorous real-world tests. You’ll find a free vs paid comparison, weekly updated rankings, and detailed insights to help you boost your blog’s traffic efficiently. Must-try options are highlighted to help you unlock your AI edge. Explore now!

10 tools
xix.ai
automation Best AI Task Routing Tools for Support Workflows
Best AI Task Routing Tools for Support Workflows

2026 Latest Best Top-rated AI Task Routing Tools for Support Workflows! XIX.AI has curated a highly powerful game-changing collection of must-try solutions, all undergoing rigorous real-world tests and updated weekly. These tools streamline workflows, boost productivity, and help teams deliver faster, more efficient support. Explore now to discover your perfect tool and unlock your AI edge!

17 tools
xix.ai
Academic Research AI Citation and Paper Summary Tools
AI Citation and Paper Summary Tools

2026 Latest Best Top-Rated AI Citation and Paper Summary Tools Curated by XIX.AI. Get powerful game-changing solutions for quick content creation, improved writing efficiency, and boosting productivity. We offer a free vs paid comparison along with real-world tests and weekly updated rankings to help you find the must-try tool that fits your needs perfectly. Explore now to Unlock your AI edge.

10 tools
xix.ai
Productivity Best AI Productivity Tools for Daily Work
Best AI Productivity Tools for Daily Work

2026 Latest Best Top-Rated AI Productivity Tools for Daily Work! XIX.AI has curated a powerful, game-changing selection based on rigorous weekly updated rankings and real-world tests. You’ll find must-try options that boost writing efficiency, streamline content creation, and help you overcome daily work challenges. Get a free vs paid comparison to find the perfect fit for your needs. Explore now to unlock your AI edge!

9 tools
xix.ai
Comments (0)
0/500
OR