JADEPUFFER, also tracked by Microsoft as Storm-3168, is a financially motivated ransomware and extortion actor targeting exposed AI workflow platforms, downstream databases, and cloud infrastructure. Its operations include credential harvesting, lateral movement, persistence, destructive database encryption, and deployment of ENCFORGE ransomware against AI and machine-learning assets. Its geographic origin is unknown, and no established nation-state affiliation has been identified. JADEPUFFER exploits CVE-2025-3248, an unauthenticated remote-code-execution vulnerability in Langflow, to execute Python on exposed systems. It enumerates compromised environments, harvests AI-provider keys and cloud credentials, probes internal services, and reuses credentials against databases and cache services. In an initial database-extortion operation, it encrypted 1,342 Nacos configuration records using MySQL's native encryption functionality, deleted the original configuration and history tables, and left a ransom demand. The captured implementation did not retain or transmit its encryption key, preventing recovery through that implementation. Its intrusion workflows feature rapid payload iteration, correction of execution failures, and extensive natural-language annotations associated with agentic AI assistance. A subsequent operation deployed ENCFORGE, a UPX-packed Go ransomware family targeting approximately 180 file extensions associated with model weights, checkpoints, vector indexes, training datasets, and related assets. JADEPUFFER abused an exposed Docker socket to create a privileged container and execute the ransomware across the container-host boundary. ENCFORGE encrypts file regions with AES-256-CTR and protects the per-run symmetric key with RSA-2048. These operations emphasize destructive encryption rather than verified data-theft extortion; neither confirmed exfiltration nor a leak site has been established. In Azure, JADEPUFFER used two compromised service principals for extensive resource discovery, storage-account key collection, and destructive operations. It attempted to delete more than 100 storage accounts within approximately seven minutes, successfully deleting most targeted accounts, and deleted application resources while also targeting backup and recovery protections. Resource locks blocked some deletions, and its Azure SQL database deletion attempts failed because it used an unsupported API version.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The operation began by exploiting an internet-facing Langflow instance through CVE-2025-3248, a missing-authentication vulnerability in a code-validation endpoint that allowed an unauthenticated attacker to execute arbitrary Python on the host.
Exploitation de CVE-2021-29441 (bypass auth Nacos) et forge de JWT via la clé de signature par défaut de Nacos.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical comparison for autonomous ransomware attacks involving adaptive agent behavior. The content does not link JADEPUFFER to the DIVD breach, which remains unattributed.
Mentioned as a comparison to the unidentified autonomous AI agent responsible for the DIVD breach. The content associates JADEPUFFER with agentic operations that leave explanatory code comments, but does not attribute the DIVD intrusion to JADEPUFFER.
Named agentic ransomware operation linked by the reporting to Storm-3168 activity; the reference does not establish that JADEPUFFER directly conducted the described Azure intrusion.
A ransomware-linked actor conducting destructive, likely automated cloud attacks. In the June 2026 Azure intrusion, it used compromised service principals for reconnaissance, credential discovery, deletion of Azure resources, and attempts to impair backup and recovery. The actor was previously associated with an LLM-orchestrated ransomware operation exploiting Langflow.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.