JADEPUFFER is an AI-agent-assisted ransomware campaign reported in 2026 that targeted exposed Langflow AI-workflow deployments. It exploited CVE-2025-3248, an unauthenticated remote-code-execution vulnerability in Langflow’s code-validation functionality, to execute Python on compromised systems. The campaign performed host and network reconnaissance, searched for cloud and API credentials, database settings, cryptocurrency-wallet material, and other secrets, and abused default credentials for accessible services. It established persistence and pivoted to production infrastructure, including environments running MySQL and Alibaba Nacos. In the Nacos phase, it abused a known default signing key to forge an authentication token, created administrative access, and encrypted more than 1,300 configuration records while leaving a ransom demand. JADEPUFFER was widely characterized as an early agentic ransomware case because its payloads included natural-language task annotations and it reportedly adapted failed actions rapidly. However, claims that the operation was fully autonomous end to end remain disputed, and the reported encryption-key handling and ransom-payment details indicate that its extortion implementation was unreliable. The campaign demonstrates the risk posed by exposed and unpatched AI workflow infrastructure, default credentials, accessible secrets, and insufficiently protected production data services. It primarily affected Linux-hosted AI and application-service environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
JADEPUFFER is described as 'Langflow-themed ransomware (CVE-2025-3248).'
Access to a production MySQL server running Alibaba Nacos (Naming and Configuration Service), using root credentials Targeting of Nacos with various payloads including exploitation of CVE-2021-29441.
On the Langflow bug, Calderone said his team believes that it’s likely the bigger concern. CVE-2026-55255 runs as an insecure direct object reference (IDOR) that lets any authenticated user execute another tenant's AI workflows, with all the secrets and credentials those flows hold.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The activity is linked to JADEPUFFER agentic ransomware operations, documented earlier in a different intrusion.
Sysdig researchers were able to detect the campaign by analyzing an attack linked to the JadePuffer threat actor that exploited a critical vulnerability in Langflow to gain initial access.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Агент обнаружил MinIO на 127.0.0.1:9000 и провёл полный цикл перечисления с дефолтными credentials
Persistence - через crontab с beacon каждые 30 минут на C2-сервер 45.131.66[.]106:4444 .
Persistence - через crontab с beacon каждые 30 минут на C2-сервер 45.131.66[.]106:4444 .
Агент обнаружил MinIO на 127.0.0.1:9000 и провёл полный цикл перечисления с дефолтными credentials
Persistence - через crontab с beacon каждые 30 минут на C2-сервер 45.131.66[.]106:4444 .
Privilege Escalation Exploited Nacos (CVE-2021-29441) to bypass authentication, forge JWTs, and create administrative access.
The marimo case is the clean demonstration: an ATA gained entry through an ordinary CVE, then composed the entire post-exploitation chain live — credential harvesting, an AWS Secrets Manager call...
The same service principal made an inventory request for Azure Storage Accounts and sent more than 30 successful ListKeys requests, asking ARM to return each storage account's access keys.
Сканирование внутреннего адресного пространства с пробингом databases, object storage, secret stores.
AI-агент провёл System Information Discovery (T1082): id , uname -a , hostname , перечисление сетевых интерфейсов и процессов.
“Over roughly seven minutes, Storm-3168 made more than 100 attempts to delete storage accounts, with most targeted accounts successfully removed. It also deleted a Key Vault, Function App, and App Service plan.”
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An agentic ransomware operation linked in the reporting to Storm-3168's Azure intrusion activity. The observed operation performed cloud-environment discovery, deleted Azure storage and other resources, targeted recovery controls, and retrieved Azure Storage account keys, consistent with a likely extortion-focused objective. The report did not confirm a ransom note or successful data theft in this incident.
An agentic ransomware operation in which an LLM reportedly drove the extortion workflow, including initial access, production database-server compromise, and data destruction. The actor associated with it was later observed using compromised Azure service principals for reconnaissance, credential collection, cloud-resource destruction, and attempts to impair backup and recovery mechanisms.
Described as fully autonomous ransomware.
Described only as an autonomous AI ransomware and contrasted with the AI-assisted, human-operated UNC-PRNT campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.