Security researchers at Sysdig said they have documented the first ransomware operation run from start to finish by an AI agent, with no human directing the keyboard. In an analysis published July 1, the company’s threat research team named the campaign JADEPUFFER and described it as the first documented case of “agentic ransomware,” a complete extortion operation driven end to end by a large language model.
The agent got in through CVE-2025-3248, a missing-authentication flaw in Langflow, a widely used open-source framework for building LLM applications, that lets an unauthenticated attacker run arbitrary code. From there it enumerated the compromised host, swept it for API keys and cloud credentials, dumped a backing Postgres database, probed object storage using default credentials, and installed a persistence mechanism that beaconed to attacker infrastructure every 30 minutes. It then pivoted to a target database server, exploited a second known vulnerability in Alibaba’s Nacos configuration service, forged authentication tokens, planted backdoor administrator accounts, and encrypted all 1,342 configuration items before dropping the original tables and leaving a ransom note.
What convinced the researchers a model was running the attack was the way it behaved. The more than 600 Python payloads it delivered contained natural-language commentary explaining each step, including its reasoning for prioritizing the “largest” database by likely payoff. It also corrected itself at a speed no human operator could match: after one backdoor insertion failed, the agent diagnosed the problem and issued a working fix 31 seconds later. When a request returned data in an unexpected format, the next payload parsed the new format; when a database deletion failed on a foreign-key constraint, the next command disabled the constraint check and tried again.
Two details underscore how blunt the operation was. The victim cannot recover the encrypted data even by paying, because the encryption key was printed once and never stored or transmitted. And the Bitcoin address in the ransom note was the canonical example address embedded throughout Bitcoin’s developer documentation, which the researchers suggest the model may have reproduced from its training data rather than generating a real wallet. Sysdig did not identify which model was used.
The significance is not the attack’s complexity, which was modest, but that an agent executed the entire chain autonomously. It fits a line of recent findings that autonomous agents are moving from research demonstrations into live intrusions, from an agent that breached McKinsey’s internal chatbot in two hours to industry data showing a rising share of breaches now involving an autonomous agent. The through-line is a falling barrier: work that once required a skilled operator can increasingly be handed to a model.
Sources: Sysdig, Dark Reading, BleepingComputer
–
By the Control Plane Editorial Team