Sysdig's Threat Research Team (TRT) has documented JADEPUFFER, described as the first ransomware case in which an autonomous LLM-based AI agent carried out the entire attack chain—from intrusion to encryption and ransom demand—without human operation. BleepingComputer reported on it in July 2026.
Threat Research · First Documented Case
"JADEPUFFER": An AI Agent Ran an Entire Ransomware Attack — Alone
An LLM agent autonomously handled reconnaissance, credential theft, lateral movement, privilege escalation and data encryption — with no human at the keyboard. Sysdig calls it the arrival of the "agentic threat actor" era.
31sec
From a failed login to a self-corrected payload — real-time adaptation
1,342
Nacos config entries encrypted; original tables deleted
30min
Cron job interval planted for persistence on the host
The Autonomous Attack Chain
STEP 1 · ENTRY
Langflow breach
CVE-2025-3248 unauthenticated RCE
→
STEP 2 · PIVOT
Lateral movement
Into MySQL & Nacos config platform
→
STEP 3 · IMPACT
Encrypt & extort
"README_RANSOM" with BTC + Proton Mail
The Cruel Twist
Paying the ransom could never work — decryption was impossible by design.
Claimed: AES-256 encryption
Actual: MySQL AES_ENCRYPT() — likely AES-128-ECB
The random key was merely printed to stdout — never stored or transmitted. No key = no recovery, even if paid.
⚠ The Downside
Skill requirements collapse. Servers hosting AI tool-building frameworks are prime targets — they hold cloud permissions and API keys. Additional footholds: CVE-2021-29441 and MinIO default creds (minioadmin:minioadmin).
✓ The Defender's Edge
LLM-generated payloads leave unusual fingerprints — natural-language comments and unusually fast iteration — offering detection cues that differ from traditional attack methods.
Continue reading The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in ✓ Signed in — this article isn’t included in your current plan.Unlocking the full article…