Sysdig Documents JADEPUFFER — The First End-to-End Autonomous AI Ransomware Operation
Sysdig Threat Research·high signal
Sysdig's Threat Research Team published a full analysis of JADEPUFFER, where an LLM agent drove an entire intrusion — exploiting a Langflow instance via CVE-2025-3248, harvesting credentials, moving laterally, escalating privileges, and running a database-extortion playbook with 600+ purposeful payloads. Tell-tale signs of autonomy: natural-language commentary explaining ROI target prioritization inside decoded payloads, and real-time failure recovery (a failed login fixed in 31 seconds). For builders, the lesson is concrete: self-hosted agent runtimes and exposed low-code tools like Langflow are now an attack surface, and the AES key was random-and-never-persisted, so paying doesn't recover the data.