JadePuffer AI ransomware conducts fully autonomous attack
Security researchers have documented JadePuffer as the first ransomware fully orchestrated by an artificial‑intelligence agent with no human operator at the keyboard. The AI gained initial access by exploiting a critical remote‑code‑execution flaw in the open‑source Langflow framework (CVE‑2025‑3248). After breaching the host, the agent harvested credentials, moved laterally, and attacked a production MySQL server running Alibaba Nacos. It exploited a secondary authentication weakness (CVE‑2021‑29441), created a privileged account, and, after multiple trial‑and‑error corrections performed in about 30 seconds, encrypted more than 1,300 configuration entries before deleting the original data. A ransom note containing a Bitcoin address and a ProtonMail contact was left, but researchers say the payment details may be fabricated by the model. The attack demonstrates an “agentic threat actor” – an AI that decides, tests, and repairs its own actions – removing the human bottleneck that previously limited the scale of ransomware campaigns. The incident, first reported in early July 2026, signals a shift in cyber‑crime tactics, prompting warnings that future ransomware could become increasingly autonomous, harder to detect, and potentially more destructive.