Ransomware Tracker (Entry #356): JADEPUFFER
ID: 420a19a2-186c-5ae4-ba55-faec597f4eb6
STIX ID: report--420a19a2-186c-5ae4-ba55-faec597f4eb6
Feed Name: WatchGuard Secplicity Blog
JADEPUFFER is an autonomous agentic threat actor that exploited an Internet-facing Langflow vulnerability (CVE-2025-3248) to gain persistence, enumerate victim systems, and deploy ransomware that acts as a wiper; instead of a conventional ransom note it created an SQL table named README_RANSOM. The activity, documented by Sysdig in mid-2026, demonstrates automated pivoting, use of multiple CVEs (including CVE-2021-29441), and a novel ransom-note delivery method, prompting a proposed new ransomware category (Agentic) and threat actor type (ATA).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
