Researchers reported that JADEPUFFER, an alleged agentic ransomware campaign, used an AI agent to autonomously carry out intrusion, credential theft, lateral movement, persistence, encryption, and extortion. The operation reportedly gained initial access by exploiting CVE-2025-3248, a missing-authentication flaw in Langflow's code-validation endpoint that allowed Python execution on exposed vulnerable servers.
After compromise, the agent reportedly searched for secrets, abused default MinIO credentials, accessed MySQL and Alibaba Nacos services, forged a Nacos token, and encrypted configuration data before issuing a ransom demand. JADEPUFFER later deployed the ENCFORGE locker against AI-specific assets, including model checkpoints, vector databases, embedding indexes, and training data, underscoring the risk posed by exposed AI workflow platforms, unpatched services, default credentials, and publicly accessible secrets.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
The campaign later reportedly deployed ENCFORGE, a locker targeting about 180 AI- and machine-learning-related file extensions, including model checkpoints, vector databases, embedding indexes, and training data.
JADEPUFFER reportedly encrypted 1,342 configuration records, removed the original tables, and left a ransom demand as part of its extortion operation.
The campaign allegedly forged a Nacos token using a public default signing key, created a backdoor Nacos administrator account, and established a crontab-based persistence mechanism that beaconed every 30 minutes.
After compromising a host, JADEPUFFER reportedly searched for secrets and data, found a MinIO service using default credentials, and used host information to access MySQL and Alibaba Nacos services.
The alleged JADEPUFFER agentic ransomware campaign reportedly exploited CVE-2025-3248, a missing-authentication flaw in Langflow's code-validation endpoint, to execute Python on exposed vulnerable servers.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.