Garp Independent AI & technology journalism
Friday, August 7, 2026 Sign In · Join Subscribe
Latest Defense tech Hadrian raises $1.37B at $8B valuation

AI news, research, models, robotics, chips, startups, and infrastructure coverage.

Updated daily

Home  /  AI News  /  Why this fully agentic ransomware attack is giving researchers nightmares

Research

Why this fully agentic ransomware attack is giving researchers nightmares

Why this fully agentic ransomware attack is giving researchers nightmares

JadePuffer could be the first reported case of a ransomware attack driven by AI from start to finish. How can businesses respond?

Security researchers have identified JadePuffer, a ransomware campaign that they're calling the "first documented case of agentic ransomware." The entire operation is driven end-to-end by AI.   Also: 5 ways to fortify your network against the new speed of AI attacks According to the cloud security firm Sysdig, JadePuffer uses a large language model (LLM) to handle the campaign without human intervention.  The JadePuffer operator — or cybercriminal group — exploited CVE-2025-3248, an unauthenticated remote code execution (RCE) vulnerability in Langflow, an open source builder for agentic AI applications.  JadePuffer's LLM abused the Langflow bug to gain initial access to its target system, performing reconnaissance and scanning the environment to steal credentials, including LLM-related API keys, cloud service credentials, cryptocurrency wallet information, and seed phrases, as well as database credentials and configuration files.  Also: Is your AI agent a security risk? NanoClaw wants to put it in a virtual cage After establishing persistence in the Langflow environment, the threat actor pivoted to its true target, a production server running an Alibaba Nacos configuration service. Ransomware was then deployed, and files on the server were encrypted before a ransom note demanding payment in Bitcoin was displayed to the victim.  This playbook has been seen countless times in ransomware campaigns, but what makes it different is its use of an LLM that can adapt and adjust its tactics based on the defenses it encounters: It appears that JadePuffer may be one of the earliest examples of a ransomware campaign deployed and managed by an LLM.  Noelle Murata, chief operating officer of Xcape Inc., says that the JadePuffer case "marks a foundational shift in adversarial capabilities," highlighting how AI can be used to pivot cyberattackers from scripted — and rigid — techniques to "autonomous, machine-speed execution." Also: 5 security tactics your business can't get wrong in the age of AI – and why they're critical