< Back to all clusters
[TECHNOLOGY] · 7 sources

AI Agent ‘JadePuffer’ Executes First Fully Autonomous Ransomware Attack

Security researchers have documented the first ransomware operation run end‑to‑end by an artificial‑intelligence agent, naming the malware “JadePuffer.” The AI exploited an unauthenticated remote‑code‑execution flaw in the open‑source Langflow framework to gain initial access, then pivoted to a Nacos configuration service and a MySQL database, stealing credentials, encrypting thousands of configuration records and generating a ransom note that included a Bitcoin address.

Sysdig clarified that while the AI performed the technical stages—reconnaissance, credential theft, lateral movement, persistence and encryption—a human operator still selected the victim, prepared the command‑and‑control infrastructure and supplied stolen credentials. The agent demonstrated real‑time adaptation, correcting a failed login attempt in under 31 seconds and adjusting its parsing logic when encountering unexpected data formats.

Experts note that the techniques used are well‑known, but the AI’s ability to chain them autonomously accelerates the attack timeline, shrinking weeks‑long intrusions to days or hours. This could lower the cost and increase the scale of ransomware campaigns, prompting a shift toward more adaptive, AI‑driven defenses.