The “first” fully agentic ransomware is here, but we aren’t panicking (yet): Meet JadePuffer
ID: a8c54aa3-c593-5e46-adc5-64deeac222fd
STIX ID: report--a8c54aa3-c593-5e46-adc5-64deeac222fd
Feed Name: Expel Blog
Threat Score
Sysdig research and reporting describe the JadePuffer campaign as an LLM-driven ransomware attack that exploited CVE-2025-3248 and used an autonomous agent to retry failed steps, but notes the attack was directed by an apparently unskilled human operator (no stored decryption keys or extortion address); the key takeaway is that responsibility and mitigation still hinge on human actors and basic security fundamentals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
