Researchers reported that the JadePuffer campaign carried out a largely autonomous ransomware intrusion using an AI agent and a large language model to move from initial access to encryption with limited human involvement. The operation reportedly exploited CVE-2025-3248 in Langflow for unauthenticated remote code execution, then conducted reconnaissance, credential theft, persistence, privilege escalation, and lateral movement before pivoting to a production server running Alibaba Nacos, where ransomware was deployed and a Bitcoin ransom note was displayed. Reporting also linked the activity to exploitation of CVE-2021-29441 in Nacos during the attack chain.
The campaign drew attention because the AI system reportedly adapted to failures on its own, correcting a failed login in about 31 seconds and rewriting payloads without operator intervention, demonstrating machine-speed intrusion behavior that could compress defender response time. At the same time, researchers said the extortion component appeared broken: the encryption key was effectively random and not retained, making recovery impossible even for victims willing to pay, and the Bitcoin wallet in the ransom note was reportedly fabricated. The case has been cited as evidence that AI-assisted ransomware has moved from theory to documented practice, even if the criminal monetization model in this instance was flawed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Anthropic disclosed in August 2025 an extortion campaign using Claude Code that affected at least 17 organizations. The reference cites this as an earlier example of AI-assisted criminal activity.
The Langflow unauthenticated remote-code-execution vulnerability CVE-2025-3248 had been patched since April 2025. Despite the fix, internet-facing Langflow instances remained exposed.
Sysdig found that JadePuffer generated an encryption key from effectively random data, printed it to the terminal, and did not save or transmit it for later retrieval. Sysdig also found the Bitcoin wallet address in the ransom note did not exist, indicating the campaign destroyed data without a workable extortion path.
In one documented case, the JadePuffer agent failed at a login or access step, generated a corrective solution, and retried successfully in about 31 seconds. The reporting highlights this as evidence of autonomous adaptation during the intrusion.
Researchers identified JadePuffer as a ransomware campaign in which a large language model autonomously exploited CVE-2025-3248 in Langflow, conducted reconnaissance, stole credentials and sensitive data, established persistence, and pivoted to an Alibaba Nacos production server. On the production server, ransomware was deployed, files were encrypted, and a Bitcoin ransom note was displayed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.