logo

JADEPUFFER: Agentic ransomware for automated database extortion

ID: 30b21946-467c-532a-9229-7bbb502a1348

STIX ID: report--30b21946-467c-532a-9229-7bbb502a1348

Feed Name: Sysdig Blog

Threat Score
78/100

Date Published: 2026-07-01

Date Updated: 2026-08-06

...
...

Sysdig TRT documents JADEPUFFER, an LLM-driven (agentic) ransomware campaign that leveraged Langflow RCE (CVE-2025-3248) to harvest credentials, pivot to an exposed MySQL/Nacos server, deploy persistence, encrypt Nacos configuration data with an unrecoverable key, drop databases, and leave ransom artifacts; the report includes captured payloads, IoCs (45.131.66.106, 64.20.53.230, Bitcoin address, cron beacon), and mitigation guidance (patch Langflow, harden Nacos, runtime DB detection, egress controls).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.