JADEPUFFER is a financially motivated ransomware and extortion actor, tracked by Microsoft as Storm-3168. It is notable for operations assessed as substantially driven by an AI agent, although human operators selected targets, provisioned infrastructure, and supplied at least some access or credentials. The actor has no established overlap with known ransomware groups or nation-state actors, and its geographic origin is unknown. JADEPUFFER exploited CVE-2025-3248 in internet-exposed Langflow deployments to obtain remote code execution. In its earlier activity, it conducted reconnaissance, harvested cloud and application credentials, accessed internal MySQL and Alibaba Nacos services, established persistence, moved laterally, and encrypted configuration data while deleting original records and issuing a ransom demand. It later deployed ENCFORGE, a Go-based ransomware family built to encrypt AI and machine-learning assets, including model artifacts, vector indexes, and training datasets. Following a failed payload-delivery attempt, the actor used iterative scripts through the compromised Langflow environment and abused exposed Docker socket access to escape container isolation and execute ransomware on the host. ENCFORGE uses hybrid encryption, terminates processes locking target files, and removes itself after execution. No confirmed data exfiltration, leak site, or payment portal was identified in the ENCFORGE activity. In a separate Azure intrusion, Storm-3168 used compromised service principals to enumerate cloud resources, seek credentials, retrieve storage-account keys, and delete storage accounts and application resources. It also targeted backup and recovery protections, Key Vaults, Function Apps, App Service plans, and Azure SQL databases. Most targeted storage-account deletions succeeded, while resource locks and deletion protection prevented some actions; SQL deletion attempts failed. The combination of destructive activity, recovery impairment, and storage-key collection was assessed as ransomware-aligned, though no ransom note or confirmed exfiltration was observed in that Azure incident.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
JADEPUFFER's earlier ransomware operation "exploited a known security flaw in Langflow (CVE-2025-3248) to break in," then harvested credentials, moved laterally, encrypted Nacos configuration files, dropped database tables, and demanded Bitcoin.
Exploitation de CVE-2021-29441 (bypass auth Nacos) et forge de JWT via la clé de signature par défaut de Nacos.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named agentic ransomware operation linked by the reporting to Storm-3168 activity; the reference does not establish that JADEPUFFER directly conducted the described Azure intrusion.
A ransomware-linked actor conducting destructive, likely automated cloud attacks. In the June 2026 Azure intrusion, it used compromised service principals for reconnaissance, credential discovery, deletion of Azure resources, and attempts to impair backup and recovery. The actor was previously associated with an LLM-orchestrated ransomware operation exploiting Langflow.
A ransomware-aligned actor conducting destructive cloud operations against Azure resources. Earlier activity exploited a Langflow flaw to access an environment, harvest credentials, move laterally, encrypt Nacos configuration files, drop database tables, and demand Bitcoin. In the Azure incident, it used compromised service principals for lengthy discovery, credential collection, deletion of storage accounts, and attempts to delete databases and recovery-related resources.
An agentic ransomware/extortion actor targeting AI and ML development infrastructure. It exploited a Langflow remote-code-execution flaw, harvested and replayed cloud/provider credentials, attempted to encrypt a production database, and later deployed the ENCFORGE ransomware binary to encrypt AI model artifacts, vector indices, training datasets, and related files. The activity appears primarily destructive/extortion-oriented rather than data-theft-focused.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.