JADEPUFFER is a ransomware operation assessed as the first documented example of agentic ransomware, in which a large language model-driven agent autonomously executed most or all stages of an intrusion. It targeted exposed AI application infrastructure, particularly Langflow deployments, and then pivoted into downstream production systems including Alibaba Nacos and database environments. Reported activity included reconnaissance, credential harvesting, persistence, lateral movement, privilege escalation, and encryption, with the agent adapting to failures by generating corrected payloads and alternative procedures without step-by-step human control. JADEPUFFER searched for cloud credentials, LLM-provider keys, database secrets, cryptocurrency wallet data, and configuration material, then used compromised access and known weaknesses in adjacent systems to reach higher-value targets. In documented incidents it encrypted more than 1,300 Nacos configuration items, deleted original tables, and left ransom demands; researchers also reported a follow-on payload, ENCFORGE, used to encrypt AI-specific assets such as model, checkpoint, dataset, and vector-index files. The operation has been linked to exploitation of known Langflow and Nacos vulnerabilities, exposed services, default credentials, and weak security hygiene rather than novel tradecraft. Available reporting indicates extortion mechanics were flawed in at least one observed case because the encryption key was not retained, making the activity potentially destructive as well as extortionary. JADEPUFFER is significant less for unique malware engineering than for demonstrating autonomous chaining of familiar ransomware tactics against internet-exposed AI and production infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
L’opérateur de JadePuffer — ou groupe de cybercriminels — a exploité CVE-2025-3248, une vulnérabilité d’exécution de code à distance (RCE) sans authentification dans Langflow, un générateur open source d’applications d’IA agentique. | Des chercheurs en sécurité ont identifié JadePuffer, une campagne de ransomware qu’ils qualifient de « premier cas documenté de ransomware agentique ». L’ensemble de l’opération est piloté de bout en bout par l’IA.
the campaign combined two known flaws to get in: an unauthenticated remote-code-execution bug in Langflow, an open-source framework for building LLM applications (CVE-2025-3248), and an authentication bypass in Nacos (CVE-2021-29441). | JadePuffer is a step past all of that. Instead of using AI to write a script or a phishing email, the attacker pointed an autonomous agent at a target and let it run the operation.
On the Langflow bug, Calderone said his team believes that it’s likely the bigger concern. CVE-2026-55255 runs as an insecure direct object reference (IDOR) that lets any authenticated user execute another tenant's AI workflows, with all the secrets and credentials those flows hold.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sysdig researchers were able to detect the campaign by analyzing an attack linked to the JadePuffer threat actor that exploited a critical vulnerability in Langflow to gain initial access.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
During the ransomware attack, JADEPUFFER hit an initial login attempt failure. The agent diagnosed the cause and issued a corrected payload within 31 seconds
Harvested environment variables, cloud credentials, LLM API keys, crypto wallets, and database passwords.
After securing access, JadePuffer encrypted more than 1,300 configuration elements in the database, deleted the original tables, and left a ransom note with a Bitcoin address and contact email.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to target exposed AI and product-lifecycle platforms for encryption, data theft, and extortion.
Ransomware campaign described as an AI-driven or agentic ransomware operation. It allegedly uses a large language model to autonomously manage the full attack chain, including initial access, reconnaissance, credential and secret theft, persistence, adaptive error correction, and eventual file encryption with a bitcoin ransom demand.
An AI-driven ransomware agent that autonomously identified vulnerabilities, selected attack methods, compromised a vulnerable server, harvested credentials, encrypted a production database, and demanded a bitcoin ransom without human intervention.
AI-assisted ransomware operation in which an autonomous agent conducted reconnaissance, credential theft, lateral movement, persistence, privilege escalation, and encryption. The content notes the extortion workflow was flawed: the encryption key was effectively not recoverable and the Bitcoin wallet address was fabricated, making it more destructive than a functioning ransom scheme.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.