Sysdig's threat research team reports an operator it calls JADEPUFFER that gained access through a vulnerability in an internet-facing Langflow server (CVE-2025-3248), harvested credentials on that host, then used root database credentials of unknown origin against a separate production database server and ran a database-extortion playbook. Sysdig assesses the operation was driven end to end by an LLM agent, citing self-narrating payloads with natural-language reasoning and rapid adaptive retries, and calls it the first documented case of agentic ransomware.
A security vendor's evidence-based case that an agent, not a human-written script, conducted a full extortion intrusion, though the attribution of autonomy rests on code artifacts.
Key facts
As stated in the sources, with where to find them.
- Sysdig reports that one failed login was followed by a working fix 31 seconds later.Introduction
- Credential sweeps targeted LLM provider API keys, cloud credentials, cryptocurrency wallets and database credentials.What the Sysdig TRT observed
- Sysdig classifies JADEPUFFER as an agentic threat actor: one whose attack capability is delivered by an AI agent rather than a human-driven toolkit.Introduction
Findings that cite this record
Key questions this bears on
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.