JADEPUFFER: Agentic ransomware for automated database extortion
ID: 30b21946-467c-532a-9229-7bbb502a1348
STIX ID: report--30b21946-467c-532a-9229-7bbb502a1348
Feed Name: Sysdig Blog
Sysdig TRT documents JADEPUFFER, an LLM-driven (agentic) ransomware campaign that leveraged Langflow RCE (CVE-2025-3248) to harvest credentials, pivot to an exposed MySQL/Nacos server, deploy persistence, encrypt Nacos configuration data with an unrecoverable key, drop databases, and leave ransom artifacts; the report includes captured payloads, IoCs (45.131.66.106, 64.20.53.230, Bitcoin address, cron beacon), and mitigation guidance (patch Langflow, harden Nacos, runtime DB detection, egress controls).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
