JadePuffer
- Profile updated
- 2026-07-28 03:00:02
Context
JADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate the entire attack chain from initial access to data destruction. It exploited CVE-2025-3248 against an exposed Langflow instance for initial access, then compromised MinIO using default credentials and manipulated MySQL for privilege escalation. The operation culminated in the encryption of over 1,300 configuration records in Nacos, with the encryption key lost, rendering the data unrecoverable. JADEPUFFER exemplifies a shift towards machine-speed extortion, where traditional security models are outpaced by automated threats.
Exploited vulnerabilities
- CVE-2025-3248 (vulnerability)
Reports & references
- thehackernews.com — New Encforge Ransomware Targets Ai (report)
- krypt3ia.wordpress.com — Threat Intelligence Report Jadepuffer Agentic Ransomware And Automated Extortion (report)
- nsfocusglobal.com — Ai Security Incident Jadepuffer Ransomware Leverages Ai Agent To Automate Attacks (report)
- securereading.com — Jadepuffer Ai Ransomware Autonomous Llm Attack (report)
- socfortress.medium.com — Jadepuffer The Dawn Of Agentic Ransomware Operations 003A59848007 (report)