Complete Data Destruction

AI Agent Executes First Fully Autonomous Ransomware Attack

AI, First Fully Autonomous Ransomware Attack, first autonomous AI agent ransomware attack, how JadePuffer conducted a ransomware attack, CVE-2025-3248, Langflow, Autonomous Ransomware Attack, AI Agent, Artificial Intelligence´
Facebook
X
LinkedIn
Reddit
WhatsApp

Security researchers at Sysdig have documented what they describe as the first fully autonomous ransomware attack executed by an AI agent.

Cybersecurity company Sysdig has reported the first documented ransomware attack carried out entirely by an autonomous AI agent. The researchers named the digital attacker JadePuffer. The AI agent gained initial access by exploiting an authentication bypass vulnerability in a publicly exposed Langflow instance. Tracked as CVE-2025-3248, the flaw allows remote attackers to execute arbitrary Python code on the target system.

Ad

In a blog post discussing the incident, Michael Clark, Director of Threat Research at Sysdig, said, “The most remarkable aspect was the behavior of the LLM.” According to Clark, JadePuffer’s malware packages contained “natural-language reasoning, target prioritization, and the kind of detailed annotations that human attackers rarely write but LLM-generated code produces almost instinctively.” The system also demonstrated real-time adaptability by correcting a failed login attempt within just 31 seconds.

Credential Theft and Lateral Movement

After gaining access, the AI agent harvested sensitive credentials, including API keys for AI providers and login credentials for cloud platforms such as Amazon Web Services (AWS), Microsoft Azure, Google Cloud, and the Chinese cloud services operated by Alibaba, Tencent, and Huawei. To maintain persistence, the system created an automated cron job on the compromised server that reconnected to the attacker’s infrastructure every 30 minutes.

JadePuffer then expanded the attack to a separate production server hosting a MySQL database and Alibaba Nacos, a service discovery and configuration management platform. The agent connected to the database using root credentials, although the origin of those credentials remains unknown. By exploiting the authorization bypass vulnerability CVE-2021-29441 and forging a JSON Web Token (JWT), the AI agent obtained elevated privileges and inserted an administrator account into the Nacos database.

Ad

AI Agent Encrypts Data, Then Carries Out Complete Data Destruction

In the final stage of the attack, the autonomous attacker encrypted all 1,342 Nacos service configuration records using MySQL’s built-in AES encryption function. It then left behind a ransom note, a Bitcoin payment address, and a contact email hosted by Proton Mail.

However, Sysdig’s researchers warn that the victim would not have been able to recover the encrypted data even if the ransom had been paid. The AI agent independently escalated its actions from deleting individual database rows to wiping entire database schemas, without first creating a backup of the encrypted data. As a result, the attack ultimately caused irreversible data destruction rather than conventional ransomware encryption.

(ll)

Ad

Artikel zu diesem Thema

Weitere Artikel