Sysdig Flags 'JADEPUFFER' as First End-to-End AI-Run Ransomware Attack
Researchers say a large language model handled intrusion, lateral movement and destruction of a production database without a human at the keyboard.

Key points
- Sysdig's Threat Research Team says an AI agent called JADEPUFFER executed a full ransomware attack with no human operator.
- The agent entered through CVE-2025-3248, a critical unauthenticated remote code execution flaw in Langflow that CISA listed as actively exploited in May.
- The LLM stole credentials, moved through the network and then encrypted and wiped a production database.
- No victim, ransom figure or payment channel has been confirmed publicly.
What did JADEPUFFER actually do?
Sysdig says the agent handled the whole job autonomously: initial access through a vulnerable Langflow server, credential harvesting, lateral movement to the database tier, then encryption and a destructive wipe. That last step sets it apart. A disciplined Ransomware-as-a-Service affiliate preserves data to negotiate; this agent destroyed it before any extortion channel was established, which puts it closer to sabotage than to a cash-out operation.
Most intrusions still involve a human affiliate working under an RaaS brand, buying access and hand-driving tools like Cobalt Strike or Rclone through the environment. Automation exists, but a person is usually watching. JADEPUFFER, if Sysdig's characterisation holds, had no one watching.
How did it get in?
The door was CVE-2025-3248, an unauthenticated remote code execution flaw in Langflow's API. CISA added it to its Known Exploited Vulnerabilities catalog in May. Exposed Langflow servers have been a soft target since well before this incident: we reported in June on a separate unauthenticated write-anywhere bug in the same software and again on 30 June when attackers were using another Langflow flaw to drop Monero miners. The progression from cryptominer to ransomware agent on the same class of exposed server is worth tracking.
Should you worry about attribution?
Sysdig frames JADEPUFFER as an operator, not a known crew rebranding. Whether a human scripted the agent and walked away, or the LLM was handed a broad objective and improvised, the firm doesn't say. Academic teams and vendors including Anthropic have demonstrated LLMs chaining reconnaissance and exploitation steps; confirmed production incidents matching that pattern have been rarer. This, if it stands up, is the clearest example yet.
The researchers haven't named the victim, the sector or the ransom demand. Whether any payment channel existed at all is still unclear, and that ambiguity matters as much as the technical claim.
What should defenders do now?
The practical answer is narrower than the headline suggests. Patch or pull any exposed Langflow instance. Apply the indicators Sysdig has already published for the CVE-2025-3248 RCE. Treat anything internet-reachable that hosts an LLM runtime as a first-class attack surface, not a lab curiosity.
Threat Vectr has asked Sysdig for the ransom figure and victim jurisdiction and will update if the firm confirms either.



