When AI agents attack: JADEPUFFER agentic ransomware raid deploys AI from start to finish

Is JADEPUFFER the first ransomware attack to bypass the human touch and use a large language model to drive the extortion operation from end-to-end? The Sysdig threat research team certainly thinks so.

They have documented the attack, which used AI agents for everything from credential theft to network traversal to data encryption. It even destroyed a production database, all in real-time.

Sysdig’s Michael Clark has confirmed that the attackers gained initial access to an internet-facing Langflow instance through CVE-2025-3248, before running “an adaptive and fully automated campaign, ultimately pivoting to the intended target and running a destructive database-extortion playbook against the victim’s production database server”.

Referring to JADEPUFFER as an agentic threat actor (ATA), Clark warned that it represents a marker for the direction in which such extortion exploits are heading. The ATA not only displayed  reasoning about its targets and harvested credentials, but “narrated its own intent the entire way”.

These self-narrated payloads, for want of a better term, employed typical natural-language reasoning and detailed annotations associated with AI agents rather than humans.

But the real killer here was the speed at which this attack was able to adapt. In one instance, JADEPUFFER moved from a failed login attempt to a completely working fix in only 31 seconds. If that doesn’t concern you as a defender, then you need to reassess your career choices, my friend.

JADEPUFFER AI ransomware agent in action
The JADEPUFFER AI ransomware agent in action (image: Sysdig)

31 seconds: AI ransomware agents shrink the window

Ram Varadarajan, CEO at Acalvio, described these 31 seconds as the skill floor for ransomware collapsing from “skilled human operator to whatever compute an agent costs to run”. As a result, he added, “unpatched internet-facing infrastructure that once sat safely in the long tail of ‘we’ll get to it’ is now the most attacked surface, not the least”.

“The conclusion is less dramatic than the predictions and more dangerous than the headlines suggest,” Shane Barney, Chief Information Security Officer at Keeper Security, told me, adding that AI agents are no longer theoretical attack surfaces but actual attack tools.

Heath Renfrow, Chief Information Security Officer at Fenix24, argues that it’s important to separate the new from an evolution of existing threat attack tradecraft.

I couldn’t agree more. JADEPUFFER and AI have not created a new ransomware threat; they have reduced the human involvement required and simultaneously sped up the entire extortion-exploitation process from start to finish.

“Large language models can now assist with reasoning through failures, adapting commands, prioritising targets and modifying attack paths in real-time,” Renfrow said. “As that capability matures, we should expect attacks to become faster, more consistent, and more scalable.”

The takeaway here, from the defender’s viewpoint, is not to be overly concerned about whether an attack is AI-powered, as the outcome won’t be any different.

“Security teams should continue prioritising the fundamental-rapid patching of internet-facing systems, strong identity protections, least privilege, network segmentation, continuous monitoring, and restricting unnecessary external exposure,” Renfrew sagely concluded.

More by Davey Winder

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.