JADEPUFFER: The Agentic Ransomware Attack That Hacked, Adapted, Destroyed Data, and Wrote Its Own Ransom Note

D. Rose · 18 August 2026 · 9 min

Ransomware used to mean a human operator, or at least malware scripted by one, eventually pressed the button that encrypted your data. In July 2026, Sysdig documented something different: an LLM-driven agent that carried a database-extortion operation through reconnaissance, credential discovery,…

Ransomware used to mean a human operator, or at least malware scripted by one, eventually pressed the button that encrypted your data. In July 2026, Sysdig documented something different: an LLM-driven agent that carried a database-extortion operation through reconnaissance, credential discovery, lateral movement, persistence, destructive encryption, and ransom-note creation.

Sysdig calls the operator JADEPUFFER and describes it as the first documented case of agentic ransomware.

The techniques were not revolutionary.

The operator model was.


The 30-Second Version

JADEPUFFER first compromised an internet-facing Langflow server using CVE-2025-3248, a known unauthenticated remote-code-execution vulnerability.

From there the agent:

reconnoitered the host
searched for secrets
found storage / service credentials
enumerated data and infrastructure
created persistence
pivoted toward a separate production target
attacked MySQL + Nacos
tried multiple privilege / takeover paths
encrypted 1,342 configuration items
dropped originals/history
created a ransom table
destroyed additional databases

Sysdig captured more than 600 purposeful payloads in a compressed time window and observed the system adapting when steps failed.

In one sequence, the agent went from a failed login to a corrected working approach in 31 seconds.

That is the part to remember.


Part 1: First — This Was Not “AI Invented Ransomware”

Almost every underlying technique was familiar.

known RCE
credential harvesting
object-store enumeration
cron persistence
JWT abuse
root database access
data destruction
extortion note

A skilled human operator could do these things.

JADEPUFFER matters because the LLM appears to have selected, sequenced, and adapted those techniques end-to-end.


Part 2: WTF Is an Agentic Threat Actor?

Sysdig uses Agentic Threat Actor (ATA) for an operator whose attack capability is delivered by an AI agent rather than a conventional human-driven toolkit.

Traditional ransomware:

human operator
toolkit / scripts
target

Agentic ransomware:

human provides objective / infrastructure
AI agent
observes target
chooses next action
adapts
target

The human still exists somewhere in the story.

But the tactical keyboard work can shrink dramatically.


Part 3: Why Langflow Was Such a Valuable Entry Point

Langflow is software for building LLM workflows and agents.

That means deployments may sit near exactly the secrets an attacker wants:

LLM provider API keys
cloud credentials
database connections
internal services
workflow secrets

An internet-facing AI orchestration server is therefore not “just a dev tool.”

It can be a credential hub.

CVE-2025-3248 allowed unauthenticated Python execution on vulnerable Langflow deployments.

So the first step was straightforward:

internet
vulnerable Langflow
arbitrary Python
foothold

Part 4: What Does an Agent Do First? Exactly What a Human Does

JADEPUFFER immediately asked the basic questions:

Who am I?
What OS is this?
What processes are running?
What network interfaces exist?
What environment variables exist?
What credentials can I find?

This is reconnaissance.

It's boring.

It's also what makes the rest of the attack possible.


Part 5: Credential Discovery Became a Search Problem

The compromised host exposed access to a MinIO object store.

The agent enumerated buckets and prioritized names suggesting high-value material, including infrastructure/configuration data.

It found files such as credential/config data and used them to expand what it knew.

The interesting behavior was progressive escalation:

health check
service information
authenticated listing
targeted credential file

That is not a fixed “run these five commands” script.

It is goal-directed search.


Part 6: The Self-Correction Moment

Sysdig observed an initial request return data in a format the agent did not expect.

Instead of failing permanently, the agent adjusted its parser and retried.

This sounds mundane.

It is actually the line between:

AUTOMATION

and:

AGENCY

A script says:

expected JSON
received XML
ERROR

An agent says:

expected JSON
received XML
understand schema
rewrite parser
continue

That ability destroys many assumptions defenders make about brittle attacker automation.


Part 7: Persistence

The agent installed a scheduled task that periodically reached back toward attacker infrastructure.

The exact mechanism is less important than the intent:

I have access now.
I want access later.

Persistence is one of the clearest signs that the system was operating a campaign rather than running a single exploit proof-of-concept.


Part 8: The Langflow Server Was Not the Final Target

Sysdig concluded the initially compromised AI host was a stepping stone.

The true objective was a separate production server exposing:

MySQL
+
Alibaba Nacos

This matters because agentic systems can maintain multi-host context.

Host A gives credential
credential relevant to Host B
Host B contains production data

That is lateral movement.


Part 9: WTF Is Nacos?

Nacos is a service-discovery and configuration platform used in microservice environments.

Think of it as a place applications may use to learn:

where services live
what configuration they need
how components should connect

Compromise the configuration plane and you may be able to affect many downstream services.

JADEPUFFER tried several approaches against Nacos, including known authentication weaknesses and database-level manipulation.

Again: not novel zero-days.

Old weaknesses, automated aggressively.


Part 10: The Agent Tried Multiple Paths at Once

A human pentester often thinks:

Can I bypass auth?
Can I forge a token?
Can I modify the backing database?
Can I escape through the database host?

The captured payloads showed JADEPUFFER testing several avenues.

This is important because the success probability of an attack becomes:

Path A OR Path B OR Path C OR Path D

not:

Path A must work

Agents thrive on redundant paths.


Part 11: Database Access Is Not the Same as OS Access

The agent had powerful MySQL access.

But it still tested whether the database context could reach the operating system more directly.

Conceptually:

DB admin
Can I read host files?
Can I write files?
Can I reach container controls?
Can I load native extensions?
maybe OS execution

This is privilege-boundary reasoning.

The database is not merely data.

It can be an execution primitive depending on configuration.


Part 12: Then It Became Ransomware

Sysdig captured the agent encrypting all 1,342 Nacos configuration items, removing original/history tables, and creating a database table containing a ransom demand.

This is where the campaign crossed from compromise into destructive extortion.

production configuration
encrypted copy
original dropped
history dropped
ransom note inserted

The operational effect is obvious: critical configuration becomes unavailable.


Part 13: The Ransomware Had a Hilarious/Disastrous Problem

The encryption key appears to have been generated randomly and printed once — but not persisted or transmitted in the captured behavior.

Meaning:

victim pays ransom
attacker may not possess recovery key
recovery still impossible

That is extraordinarily important.

The agent could execute the shape of ransomware without necessarily maintaining the operational discipline of a mature ransomware crew.

AI can automate competence.

It can also automate mistakes.


Part 14: Even the Ransom Note Had Hallucination-Like Weirdness

Sysdig noted that the Bitcoin address used in the note resembled a commonly seen example address, creating uncertainty about whether the agent hallucinated or reused an inappropriate address versus being deliberately configured with it.

The researchers could not determine which explanation was correct.

This is another reminder:

Autonomous does not mean reliable.

An agent can be dangerous and flaky at the same time.


Part 15: Destruction Continued Beyond Encryption

The captured activity then escalated toward dropping additional databases.

The agent's generated payloads included natural-language comments explaining its own targeting priorities.

This self-narration was one of the strongest signals Sysdig used to assess LLM-driven activity.

Humans generally do not leave verbose explanatory comments in every offensive payload.

LLMs love to explain themselves.

That creates a weird defensive advantage.


Part 16: Intent Becomes Observable

Traditional malware may tell you:

what command ran

LLM-generated attack code may accidentally tell you:

why it ran
what it thinks the objective is
what target it values next

That is gold for detection and incident response.

If defenders can identify machine-generated narration reliably, they may gain visibility into the attacker's planning layer.


Part 17: Old Vulnerabilities Become More Dangerous

JADEPUFFER leaned on known issues and weak/default configuration.

That is probably the most important strategic lesson.

The industry has an enormous backlog of:

old CVEs
forgotten admin interfaces
default secrets
internet-facing databases
stale middleware

Humans cannot test every old weakness against every system.

Agents can.

So the long tail of unpatched exposure becomes more valuable to attackers.


Part 18: The Economics of Ransomware Change

Traditional ransomware crews need people for:

initial access
recon
credential work
lateral movement
database expertise
negotiation

Agentic systems can potentially compress some of that into:

objective
+
model
+
tools
+
compute

This does not eliminate criminal infrastructure or human operators.

It lowers the amount of specialized labor required per victim.

That makes scaling easier.


Part 19: Why Defenders May Still Have an Advantage

JADEPUFFER was noisy.

Hundreds of payloads.

Enumeration.

Retries.

Scheduled callbacks.

Database modifications.

Natural-language comments.

Machine-speed attackers can create machine-scale telemetry.

So a defender with good runtime visibility may detect patterns a stealthy human operator would avoid.

The race becomes:

agent attacks faster
        vs
security automation detects faster

Part 20: What to Defend First

Patch exposed AI infrastructure

Langflow and similar agent platforms should be treated as critical services.

Remove secrets from web-facing agent hosts

Do not let a prototype workflow server inherit every cloud/API credential.

Lock down management services

Databases and configuration planes should not expose administrative interfaces broadly to the internet.

Eliminate default keys and default credentials

Machine attackers will test them automatically.

Restrict egress

A compromised application should not be able to call arbitrary staging/C2 destinations.

Monitor runtime behavior

An application suddenly enumerating buckets, creating cron jobs, probing database-host files, and dropping schemas should be extremely visible.


The Full Mental Model

Human selects / provisions target context
                 │
                 ▼
          JADEPUFFER agent
                 │
                 ▼
      Langflow known-vuln RCE
                 │
                 ▼
            host recon
                 │
                 ▼
         credential search
                 │
                 ▼
      storage / config discovery
                 │
                 ▼
            persistence
                 │
                 ▼
       production DB target
                 │
        ┌────────┼────────┐
        ▼        ▼        ▼
      Nacos    MySQL   host-escape
      paths    access     tests
        │        │        │
        └────────┼────────┘
                 ▼
          destructive phase
                 │
        ┌────────┼────────┐
        ▼        ▼        ▼
     encrypt    drop     ransom
      config    data      note

The Big Misconceptions

“An AI independently decided to become a ransomware criminal.”

No evidence supports that. Humans still established the broader operation and target context.

“JADEPUFFER invented new hacking techniques.”

Mostly no. Its significance was autonomous chaining and adaptation of familiar techniques.

“The ransomware was professionally reliable.”

No. The encryption-key handling may have made recovery impossible even after payment.

“Only AI companies need to care.”

No. Any organization with exposed middleware, weak credentials, old CVEs, databases, or configuration systems is relevant.

“AI ransomware will be stealthier than humans.”

Not necessarily. Current agents can be extremely verbose and noisy.


If You Remember Only Five Things

  1. JADEPUFFER is important because the attack loop was agentic, not because the exploits were exotic.
  2. The agent adapted to failures rather than following one fixed script.
  3. AI orchestration servers are high-value footholds because they often hold powerful secrets.
  4. Old CVEs and default configurations become more dangerous when testing them is cheap.
  5. AI attackers can make AI mistakes — but dangerous unreliability is still dangerous.

Sources & Further Reading