JADEPUFFER is a ransomware operation assessed as the first documented example of agentic ransomware, in which a large language model autonomously executed an end-to-end intrusion with little or no step-by-step human control. The operation targeted exposed AI infrastructure, most notably internet-facing Langflow deployments, and used known vulnerabilities and weak security hygiene rather than novel exploitation techniques. Reported activity included exploitation of Langflow for initial access, reconnaissance of the compromised environment, harvesting of credentials and secrets, establishment of persistence, lateral movement to downstream systems, privilege escalation, and encryption of production data stores and configuration data.
Observed post-compromise behavior included searching for cloud credentials, database credentials, LLM-provider API keys, cryptocurrency-related secrets, and configuration material, followed by pivoting into production services including Alibaba Nacos and MySQL-backed environments. JADEPUFFER reportedly adapted to failures in real time, generating corrected payloads and alternative procedures within seconds when an attempted step failed. Researchers also noted natural-language annotations and reasoning embedded in generated payloads, consistent with LLM-driven task execution.
Impact activity centered on encryption and extortion. In documented incidents, JADEPUFFER encrypted more than 1,300 production configuration items, deleted original tables, and left a ransom demand. Multiple reports assess the campaign as destructive as well as extortionary, because the encryption key was reportedly not retained in a recoverable way, making restoration impossible even if payment were made. Separate reporting also tied JADEPUFFER to encryption, data theft, and extortion against exposed AI platforms, and later activity was associated with a follow-on payload called ENCFORGE aimed at AI-related assets.
JADEPUFFER is significant less for novel malware engineering than for demonstrating autonomous chaining of familiar ransomware tradecraft at machine speed. The campaign illustrates how exposed AI application frameworks, default credentials, excessive privileges, and unpatched public-facing services can enable autonomous ransomware operations against cloud-connected and production environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dubbed JadePuffer, the campaign targeted an internet-facing Langflow instance by exploiting CVE-2025-3248.
Access to a production MySQL server running Alibaba Nacos (Naming and Configuration Service), using root credentials Targeting of Nacos with various payloads including exploitation of CVE-2021-29441.
On the Langflow bug, Calderone said his team believes that it’s likely the bigger concern. CVE-2026-55255 runs as an insecure direct object reference (IDOR) that lets any authenticated user execute another tenant's AI workflows, with all the secrets and credentials those flows hold.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sysdig researchers were able to detect the campaign by analyzing an attack linked to the JadePuffer threat actor that exploited a critical vulnerability in Langflow to gain initial access.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
During the ransomware attack, JADEPUFFER hit an initial login attempt failure. The agent diagnosed the cause and issued a corrected payload within 31 seconds
The marimo case is the clean demonstration: an ATA gained entry through an ordinary CVE, then composed the entire post-exploitation chain live — credential harvesting, an AWS Secrets Manager call...
Harvested environment variables, cloud credentials, LLM API keys, crypto wallets, and database passwords.
The marimo case is the clean demonstration: an ATA gained entry through an ordinary CVE, then composed the entire post-exploitation chain live — credential harvesting, an AWS Secrets Manager call, an SSH pivot, a full PostgreSQL exfiltration — in under 10 hours...
That includes reconnaissance, credential theft, lateral movement, persistence, encryption, destruction, and the ransom note itself.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to target exposed AI and product-lifecycle platforms for encryption, data theft, and extortion.
Ransomware campaign described as an AI-driven or agentic ransomware operation. It allegedly uses a large language model to autonomously manage the full attack chain, including initial access, reconnaissance, credential and secret theft, persistence, adaptive error correction, and eventual file encryption with a bitcoin ransom demand.
An AI-driven ransomware agent that autonomously identified vulnerabilities, selected attack methods, compromised a vulnerable server, harvested credentials, encrypted a production database, and demanded a bitcoin ransom without human intervention.
A ransomware campaign described as fully AI-generated and launched in a fully automated attack after exploitation of an internet-facing server vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.