AUTO-UPDATED

Experts warn of the 'first documented case of agentic ransomware' — dangerous JADEPUFFER attack run entirely by an LLM

Sysdig researchers have identified JADEPUFFER, the first fully autonomous ransomware attack driven by a large language model that exploits vulnerabilities to target cloud-based databases and configuration services.

Key Points

  • The JADEPUFFER attack exploited a known vulnerability in Langflow, identified as CVE-2025-3248, to gain unauthorized access to systems.
  • The autonomous agent targeted Alibaba Nacos and MySQL databases, encrypting 1,342 configuration items and dropping critical database tables.
  • The ransomware failed to create backups or encryption keys, meaning victim data remains unrecoverable even if ransom demands are met.
  • Researchers noted the agent adapted to obstacles in real-time by sharing its internal rationale, a behavior that aids in detection.
  • Langflow released a patch for the exploited vulnerability in April 2025 to prevent such unauthorized access.

Why it Matters

The emergence of agentic ransomware signals a shift toward automated, low-effort cybercrime that can learn and improve without human intervention. This development forces organizations to prioritize rapid patching and advanced behavioral monitoring to defend against increasingly intelligent and autonomous threat actors.
TechRadar Published by Christian Cawley
Read original