JADEPUFFER: first documented LLM-driven ransomware operation
Sysdig captured a ransomware operation run end to end by an LLM agent. It entered through an internet-facing Langflow server, harvested and reused credentials, moved laterally, set up persistence and destroyed a production database, correcting its own failures along the way.
- Disclosed
- Jul 2026
- Organization
- Undisclosed
- Vendor
- Unknown
- Kind of AI
- Autonomous agent
- AI's role
- Attacker used AI
- How it happened
- AI-run attack: Autonomous intrusion
- Harm
- Exposed and destroyed
- Data involved
- Credentials
- Reach
- One organization
- Severity
- High
- Model at fault
- No
- Status
- Confirmed
- Vulnerability IDs
- CVE-2025-3248