# JADEPUFFER: The Agentic Ransomware Attack That Hacked, Adapted, Destroyed Data, and Wrote Its Own Ransom Note

*D. Rose · 18 August 2026 · 9 min*

> Ransomware used to mean a human operator, or at least malware scripted by one, eventually pressed the button that encrypted your data. In July 2026, Sysdig documented something different: an LLM-driven agent that carried a database-extortion operation through reconnaissance, credential discovery,…

**Ransomware used to mean a human operator, or at least malware scripted by one, eventually pressed the button that encrypted your data. In July 2026, Sysdig documented something different: an LLM-driven agent that carried a database-extortion operation through reconnaissance, credential discovery, lateral movement, persistence, destructive encryption, and ransom-note creation.**

Sysdig calls the operator **JADEPUFFER** and describes it as the first documented case of **agentic ransomware**.

The techniques were not revolutionary.

The operator model was.

---

## The 30-Second Version

JADEPUFFER first compromised an internet-facing **Langflow** server using **CVE-2025-3248**, a known unauthenticated remote-code-execution vulnerability.

From there the agent:

```text
reconnoitered the host
        ↓
searched for secrets
        ↓
found storage / service credentials
        ↓
enumerated data and infrastructure
        ↓
created persistence
        ↓
pivoted toward a separate production target
        ↓
attacked MySQL + Nacos
        ↓
tried multiple privilege / takeover paths
        ↓
encrypted 1,342 configuration items
        ↓
dropped originals/history
        ↓
created a ransom table
        ↓
destroyed additional databases
```

Sysdig captured more than 600 purposeful payloads in a compressed time window and observed the system adapting when steps failed.

In one sequence, the agent went from a failed login to a corrected working approach in **31 seconds**.

That is the part to remember.

---

# Part 1: First — This Was Not “AI Invented Ransomware”

Almost every underlying technique was familiar.

```text
known RCE
credential harvesting
object-store enumeration
cron persistence
JWT abuse
root database access
data destruction
extortion note
```

A skilled human operator could do these things.

JADEPUFFER matters because the LLM appears to have **selected, sequenced, and adapted those techniques end-to-end**.

---

# Part 2: WTF Is an Agentic Threat Actor?

Sysdig uses **Agentic Threat Actor (ATA)** for an operator whose attack capability is delivered by an AI agent rather than a conventional human-driven toolkit.

Traditional ransomware:

```text
human operator
      ↓
toolkit / scripts
      ↓
target
```

Agentic ransomware:

```text
human provides objective / infrastructure
            ↓
         AI agent
            ↓
       observes target
            ↓
      chooses next action
            ↓
          adapts
            ↓
          target
```

The human still exists somewhere in the story.

But the tactical keyboard work can shrink dramatically.

---

# Part 3: Why Langflow Was Such a Valuable Entry Point

Langflow is software for building LLM workflows and agents.

That means deployments may sit near exactly the secrets an attacker wants:

```text
LLM provider API keys
cloud credentials
database connections
internal services
workflow secrets
```

An internet-facing AI orchestration server is therefore not “just a dev tool.”

It can be a **credential hub**.

CVE-2025-3248 allowed unauthenticated Python execution on vulnerable Langflow deployments.

So the first step was straightforward:

```text
internet
   ↓
vulnerable Langflow
   ↓
arbitrary Python
   ↓
foothold
```

---

# Part 4: What Does an Agent Do First? Exactly What a Human Does

JADEPUFFER immediately asked the basic questions:

```text
Who am I?
What OS is this?
What processes are running?
What network interfaces exist?
What environment variables exist?
What credentials can I find?
```

This is reconnaissance.

It's boring.

It's also what makes the rest of the attack possible.

---

# Part 5: Credential Discovery Became a Search Problem

The compromised host exposed access to a MinIO object store.

The agent enumerated buckets and prioritized names suggesting high-value material, including infrastructure/configuration data.

It found files such as credential/config data and used them to expand what it knew.

The interesting behavior was **progressive escalation**:

```text
health check
   ↓
service information
   ↓
authenticated listing
   ↓
targeted credential file
```

That is not a fixed “run these five commands” script.

It is goal-directed search.

---

# Part 6: The Self-Correction Moment

Sysdig observed an initial request return data in a format the agent did not expect.

Instead of failing permanently, the agent adjusted its parser and retried.

This sounds mundane.

It is actually the line between:

```text
AUTOMATION
```

and:

```text
AGENCY
```

A script says:

```text
expected JSON
received XML
ERROR
```

An agent says:

```text
expected JSON
received XML
understand schema
rewrite parser
continue
```

That ability destroys many assumptions defenders make about brittle attacker automation.

---

# Part 7: Persistence

The agent installed a scheduled task that periodically reached back toward attacker infrastructure.

The exact mechanism is less important than the intent:

```text
I have access now.
I want access later.
```

Persistence is one of the clearest signs that the system was operating a campaign rather than running a single exploit proof-of-concept.

---

# Part 8: The Langflow Server Was Not the Final Target

Sysdig concluded the initially compromised AI host was a stepping stone.

The true objective was a separate production server exposing:

```text
MySQL
+
Alibaba Nacos
```

This matters because agentic systems can maintain multi-host context.

```text
Host A gives credential
      ↓
credential relevant to Host B
      ↓
Host B contains production data
```

That is lateral movement.

---

# Part 9: WTF Is Nacos?

Nacos is a service-discovery and configuration platform used in microservice environments.

Think of it as a place applications may use to learn:

```text
where services live
what configuration they need
how components should connect
```

Compromise the configuration plane and you may be able to affect many downstream services.

JADEPUFFER tried several approaches against Nacos, including known authentication weaknesses and database-level manipulation.

Again: not novel zero-days.

Old weaknesses, automated aggressively.

---

# Part 10: The Agent Tried Multiple Paths at Once

A human pentester often thinks:

```text
Can I bypass auth?
Can I forge a token?
Can I modify the backing database?
Can I escape through the database host?
```

The captured payloads showed JADEPUFFER testing several avenues.

This is important because the success probability of an attack becomes:

```text
Path A OR Path B OR Path C OR Path D
```

not:

```text
Path A must work
```

Agents thrive on redundant paths.

---

# Part 11: Database Access Is Not the Same as OS Access

The agent had powerful MySQL access.

But it still tested whether the database context could reach the operating system more directly.

Conceptually:

```text
DB admin
   ↓
Can I read host files?
Can I write files?
Can I reach container controls?
Can I load native extensions?
   ↓
maybe OS execution
```

This is privilege-boundary reasoning.

The database is not merely data.

It can be an execution primitive depending on configuration.

---

# Part 12: Then It Became Ransomware

Sysdig captured the agent encrypting all **1,342 Nacos configuration items**, removing original/history tables, and creating a database table containing a ransom demand.

This is where the campaign crossed from compromise into destructive extortion.

```text
production configuration
        ↓
encrypted copy
        ↓
original dropped
        ↓
history dropped
        ↓
ransom note inserted
```

The operational effect is obvious: critical configuration becomes unavailable.

---

# Part 13: The Ransomware Had a Hilarious/Disastrous Problem

The encryption key appears to have been generated randomly and printed once — but not persisted or transmitted in the captured behavior.

Meaning:

```text
victim pays ransom
      ↓
attacker may not possess recovery key
      ↓
recovery still impossible
```

That is extraordinarily important.

The agent could execute the **shape** of ransomware without necessarily maintaining the operational discipline of a mature ransomware crew.

AI can automate competence.

It can also automate mistakes.

---

# Part 14: Even the Ransom Note Had Hallucination-Like Weirdness

Sysdig noted that the Bitcoin address used in the note resembled a commonly seen example address, creating uncertainty about whether the agent hallucinated or reused an inappropriate address versus being deliberately configured with it.

The researchers could not determine which explanation was correct.

This is another reminder:

> Autonomous does not mean reliable.

An agent can be dangerous and flaky at the same time.

---

# Part 15: Destruction Continued Beyond Encryption

The captured activity then escalated toward dropping additional databases.

The agent's generated payloads included natural-language comments explaining its own targeting priorities.

This self-narration was one of the strongest signals Sysdig used to assess LLM-driven activity.

Humans generally do not leave verbose explanatory comments in every offensive payload.

LLMs love to explain themselves.

That creates a weird defensive advantage.

---

# Part 16: Intent Becomes Observable

Traditional malware may tell you:

```text
what command ran
```

LLM-generated attack code may accidentally tell you:

```text
why it ran
what it thinks the objective is
what target it values next
```

That is gold for detection and incident response.

If defenders can identify machine-generated narration reliably, they may gain visibility into the attacker's planning layer.

---

# Part 17: Old Vulnerabilities Become More Dangerous

JADEPUFFER leaned on known issues and weak/default configuration.

That is probably the most important strategic lesson.

The industry has an enormous backlog of:

```text
old CVEs
forgotten admin interfaces
default secrets
internet-facing databases
stale middleware
```

Humans cannot test every old weakness against every system.

Agents can.

So the long tail of unpatched exposure becomes more valuable to attackers.

---

# Part 18: The Economics of Ransomware Change

Traditional ransomware crews need people for:

```text
initial access
recon
credential work
lateral movement
database expertise
negotiation
```

Agentic systems can potentially compress some of that into:

```text
objective
+
model
+
tools
+
compute
```

This does not eliminate criminal infrastructure or human operators.

It lowers the amount of specialized labor required per victim.

That makes scaling easier.

---

# Part 19: Why Defenders May Still Have an Advantage

JADEPUFFER was noisy.

Hundreds of payloads.

Enumeration.

Retries.

Scheduled callbacks.

Database modifications.

Natural-language comments.

Machine-speed attackers can create machine-scale telemetry.

So a defender with good runtime visibility may detect patterns a stealthy human operator would avoid.

The race becomes:

```text
agent attacks faster
        vs
security automation detects faster
```

---

# Part 20: What to Defend First

### Patch exposed AI infrastructure

Langflow and similar agent platforms should be treated as critical services.

### Remove secrets from web-facing agent hosts

Do not let a prototype workflow server inherit every cloud/API credential.

### Lock down management services

Databases and configuration planes should not expose administrative interfaces broadly to the internet.

### Eliminate default keys and default credentials

Machine attackers will test them automatically.

### Restrict egress

A compromised application should not be able to call arbitrary staging/C2 destinations.

### Monitor runtime behavior

An application suddenly enumerating buckets, creating cron jobs, probing database-host files, and dropping schemas should be extremely visible.

---

# The Full Mental Model

```text
Human selects / provisions target context
                 │
                 ▼
          JADEPUFFER agent
                 │
                 ▼
      Langflow known-vuln RCE
                 │
                 ▼
            host recon
                 │
                 ▼
         credential search
                 │
                 ▼
      storage / config discovery
                 │
                 ▼
            persistence
                 │
                 ▼
       production DB target
                 │
        ┌────────┼────────┐
        ▼        ▼        ▼
      Nacos    MySQL   host-escape
      paths    access     tests
        │        │        │
        └────────┼────────┘
                 ▼
          destructive phase
                 │
        ┌────────┼────────┐
        ▼        ▼        ▼
     encrypt    drop     ransom
      config    data      note
```

---

# The Big Misconceptions

## “An AI independently decided to become a ransomware criminal.”

No evidence supports that. Humans still established the broader operation and target context.

## “JADEPUFFER invented new hacking techniques.”

Mostly no. Its significance was autonomous chaining and adaptation of familiar techniques.

## “The ransomware was professionally reliable.”

No. The encryption-key handling may have made recovery impossible even after payment.

## “Only AI companies need to care.”

No. Any organization with exposed middleware, weak credentials, old CVEs, databases, or configuration systems is relevant.

## “AI ransomware will be stealthier than humans.”

Not necessarily. Current agents can be extremely verbose and noisy.

---

# If You Remember Only Five Things

1. **JADEPUFFER is important because the attack loop was agentic, not because the exploits were exotic.**
2. **The agent adapted to failures rather than following one fixed script.**
3. **AI orchestration servers are high-value footholds because they often hold powerful secrets.**
4. **Old CVEs and default configurations become more dangerous when testing them is cheap.**
5. **AI attackers can make AI mistakes — but dangerous unreliability is still dangerous.**

---

# Sources & Further Reading

- Sysdig Threat Research Team — JADEPUFFER: Agentic ransomware for automated database extortion: https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
- NVD — CVE-2025-3248 (Langflow): https://nvd.nist.gov/vuln/detail/CVE-2025-3248
- Dark Reading — JadePuffer coverage: https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack
