First fully autonomous AI-agent ransomware attack (JadePuffer)
Security firm Sysdig documented what it calls the first ransomware operation run almost entirely by an autonomous AI agent, tracked as JadePuffer. The agent exploited a Langflow flaw, moved through the network, and encrypted data without a human operator at the keyboard.
Researchers at Sysdig say they identified the first documented ransomware attack carried out almost entirely by an autonomous large language model agent, linked to an operation they call JadePuffer. The agent gained access through a Langflow remote code execution flaw, then handled reconnaissance, credential theft, lateral movement, persistence and privilege escalation on its own. When a login failed, it adapted and produced a working fix in about thirty one seconds. It reached a production database and encrypted over thirteen hundred configuration items before deleting the originals. According to the researchers, the encryption key was never sent back to the attackers, meaning even paying the ransom would not have restored the data. A human still provisioned the infrastructure and chose the victim, but every technical decision after that was made by the AI. Source: Sysdig, BleepingComputer.