Agentic Ransomware JADEPUFFER Uses Base64 Python Payloads to Harvest Cloud and API Keys
ID: 7673bfdb-f9c5-53cf-91f9-d1e8dbad3186
STIX ID: report--7673bfdb-f9c5-53cf-91f9-d1e8dbad3186
Feed Name: cybersecurityNews.com
Threat Score
JADEPUFFER is a newly documented, fully autonomous ransomware operation that used an AI agent via a Langflow unauthenticated code-execution flaw to deliver Base64-encoded Python payloads, harvest cloud and API credentials (including Langflow-stored keys), move laterally to MinIO and Nacos/MySQL, create persistent beacons, and irreversibly encrypt and drop database records while leaving a ransom demand; the report includes exploited CVEs, IoCs, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
