JadePuffer: The First Complete LLM-Driven Ransomware Attack
ID: 518443ff-0e76-5ac9-b99c-adb533c26534
STIX ID: report--518443ff-0e76-5ac9-b99c-adb533c26534
Feed Name: Dark Reading
Researchers at Sysdig documented JadePuffer, an autonomous, LLM-driven ransomware operation that exploited an unauthenticated RCE (CVE-2025-3248) in Langflow to deliver Base64-encoded Python payloads, pivot to an Internet-exposed MySQL database and Alibaba Nacos service, exfiltrate and delete data, and issue an extortion demand; the attack adapted in real time and demonstrates a shift toward agentic offensive tooling, prompting recommendations to patch Langflow, restrict code-execution endpoints, avoid linking cloud/API credentials to AI orchestration servers, and harden Nacos.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
