logo

Ransomware Tracker (Entry #356): JADEPUFFER

ID: 420a19a2-186c-5ae4-ba55-faec597f4eb6

STIX ID: report--420a19a2-186c-5ae4-ba55-faec597f4eb6

Feed Name: WatchGuard Secplicity Blog

Threat Score
80/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Ryan Estes

...
...

JADEPUFFER is an autonomous agentic threat actor that exploited an Internet-facing Langflow vulnerability (CVE-2025-3248) to gain persistence, enumerate victim systems, and deploy ransomware that acts as a wiper; instead of a conventional ransom note it created an SQL table named README_RANSOM. The activity, documented by Sysdig in mid-2026, demonstrates automated pivoting, use of multiple CVEs (including CVE-2021-29441), and a novel ransom-note delivery method, prompting a proposed new ransomware category (Agentic) and threat actor type (ATA).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.