Researchers and sector defenders reported that JADEPUFFER carried out what is being described as the first documented agentic ransomware attack, using an autonomous AI agent to execute an intrusion chain with little or no step-by-step human control. The attack began with exploitation of CVE-2025-3248 in an internet-facing Langflow instance, followed by credential harvesting, pivoting through a storage server that reportedly used default administrator credentials, persistence, and lateral movement toward a production database environment. Sysdig said the malware showed signs of autonomous decision-making, including adapting after failed authentication attempts and embedding natural-language behavior descriptions in code.
The operation ultimately encrypted more than 1,300 configuration entries, deleted additional data, and displayed a Bitcoin ransom note. Researchers said the ransomware did not retain or transmit the decryption key, meaning victims could be unable to recover data even if a ransom were paid. WaterISAC warned that the case demonstrates how AI agents could automate familiar attack techniques at speed and lower the barrier to ransomware operations, and urged organizations to patch Langflow, limit internet exposure of AI-related systems, and review credential storage, database administration access, and other externally reachable services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Sysdig characterized JADEPUFFER as what it believes is the first documented end-to-end ransomware attack executed by an autonomous AI agent with limited or no step-by-step human operation. The reporting emphasized autonomous chaining of known intrusion techniques rather than novel exploitation methods.
The ransomware encrypted more than 1,300 configuration entries or records, deleted additional data, and displayed a Bitcoin ransom note. Researchers said the malware did not retain or transmit the decryption key, making recovery impossible even if a victim paid.
Following initial access, JADEPUFFER reportedly used harvested credentials and a storage server with default administrator credentials to establish persistence and move laterally to a production database server. The activity was described as showing autonomous adaptation, including self-correction after failed authentication attempts.
Researchers reported that the JADEPUFFER intrusion began by exploiting CVE-2025-3248 in an internet-facing Langflow instance. After initial access, the malware harvested credentials and pivoted further into the environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcewaterisac.org
Open sourcecysecurity.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.