JADEPUFFER is an AI-agent-assisted ransomware operation associated with the cybercriminal actor Storm-3168. It uses a large language model to orchestrate reconnaissance, credential theft, lateral movement, persistence, and destructive database encryption. Its agent-driven workflow adapts payloads and retries unsuccessful actions, although the extent of human oversight is not established consistently.
Initial access exploits CVE-2025-3248, an unauthenticated remote-code-execution vulnerability in Langflow, to execute Python payloads on exposed AI-workflow servers. The operation enumerates systems and internal services, searches for cloud credentials, LLM API keys, database secrets, and cryptocurrency recovery information, and abuses default MinIO credentials. It establishes persistence through scheduled tasks and pivots to production systems running MySQL and Alibaba Nacos. By abusing Nacos authentication weaknesses and database access, it creates a backdoor administrator account, encrypts more than 1,300 configuration records, deletes original data, and leaves a cryptocurrency ransom demand.
JADEPUFFER targets enterprise AI infrastructure and associated production data services. Its destructive impact can exceed its ability to conduct viable extortion: in a documented intrusion, the encryption key was not retained for recovery and the ransom payment destination was invalid.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Unauthenticated flow build vulnerability exploited by the JadePuffer ransomware campaign to access PostgreSQL databases.
Access to a production MySQL server running Alibaba Nacos (Naming and Configuration Service), using root credentials Targeting of Nacos with various payloads including exploitation of CVE-2021-29441.
On the Langflow bug, Calderone said his team believes that it’s likely the bigger concern. CVE-2026-55255 runs as an insecure direct object reference (IDOR) that lets any authenticated user execute another tenant's AI workflows, with all the secrets and credentials those flows hold.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The activity is linked to JADEPUFFER agentic ransomware operations, documented earlier in a different intrusion.
Sysdig researchers were able to detect the campaign by analyzing an attack linked to the JadePuffer threat actor that exploited a critical vulnerability in Langflow to gain initial access.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Агент обнаружил MinIO на 127.0.0.1:9000 и провёл полный цикл перечисления с дефолтными credentials
Persistence - через crontab с beacon каждые 30 минут на C2-сервер 45.131.66[.]106:4444 .
Persistence - через crontab с beacon каждые 30 минут на C2-сервер 45.131.66[.]106:4444 .
Агент обнаружил MinIO на 127.0.0.1:9000 и провёл полный цикл перечисления с дефолтными credentials
Persistence - через crontab с beacon каждые 30 минут на C2-сервер 45.131.66[.]106:4444 .
Privilege Escalation Exploited Nacos (CVE-2021-29441) to bypass authentication, forge JWTs, and create administrative access.
The marimo case is the clean demonstration: an ATA gained entry through an ordinary CVE, then composed the entire post-exploitation chain live — credential harvesting, an AWS Secrets Manager call...
The same service principal made an inventory request for Azure Storage Accounts and sent more than 30 successful ListKeys requests, asking ARM to return each storage account's access keys.
Сканирование внутреннего адресного пространства с пробингом databases, object storage, secret stores.
AI-агент провёл System Information Discovery (T1082): id , uname -a , hostname , перечисление сетевых интерфейсов и процессов.
“Over roughly seven minutes, Storm-3168 made more than 100 attempts to delete storage accounts, with most targeted accounts successfully removed. It also deleted a Key Vault, Function App, and App Service plan.”
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An agentic ransomware operation linked in the reporting to Storm-3168's Azure intrusion activity. The observed operation performed cloud-environment discovery, deleted Azure storage and other resources, targeted recovery controls, and retrieved Azure Storage account keys, consistent with a likely extortion-focused objective. The report did not confirm a ransom note or successful data theft in this incident.
An agentic ransomware operation in which an LLM reportedly drove the extortion workflow, including initial access, production database-server compromise, and data destruction. The actor associated with it was later observed using compromised Azure service principals for reconnaissance, credential collection, cloud-resource destruction, and attempts to impair backup and recovery mechanisms.
Described as fully autonomous ransomware.
Described only as an autonomous AI ransomware and contrasted with the AI-assisted, human-operated UNC-PRNT campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.