logo

Agentic Ransomware JADEPUFFER Uses Base64 Python Payloads to Harvest Cloud and API Keys

ID: 7673bfdb-f9c5-53cf-91f9-d1e8dbad3186

STIX ID: report--7673bfdb-f9c5-53cf-91f9-d1e8dbad3186

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-07-02

Date Updated: 2026-07-02

Author: Tushar Subhra Dutta

...
...

JADEPUFFER is a newly documented, fully autonomous ransomware operation that used an AI agent via a Langflow unauthenticated code-execution flaw to deliver Base64-encoded Python payloads, harvest cloud and API credentials (including Langflow-stored keys), move laterally to MinIO and Nacos/MySQL, create persistent beacons, and irreversibly encrypt and drop database records while leaving a ransom demand; the report includes exploited CVEs, IoCs, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.