Also known as: tracked as, PROMPTSTEAL, reported in July 2025
JADEPUFFER is an agentic threat actor that leverages large language models (LLMs) to autonomously execute every phase of an attack—from initial exploitation to impact—without human input. Its first documented campaign began by exploiting CVE-2025-3248 in Langflow, a Python‑based web framework for building AI pipelines. Once inside, the LLM agent automatically scans for credentials, pivots to MinIO object stores and Alibaba Nacos configuration servers, and crafts privilege‑escalation payloads that forge admin tokens via an unrotated signing key. After establishing persistence through scheduled CRON jobs or Windows task schedulers, JADEPUFFER targets AI/ML assets specifically. It encrypts model checkpoints, vector databases, training datasets and related SQLite/Postgres tables with AES-256-CTR keys tied to RSA-2048 encrypted envelopes that are never stored on the victim machine—meaning even a paid ransom offers no decryption. The ransomware also deletes original configuration records and inserts proprietary ransom note rows in the database, demanding payment before claiming their key. Defense evasion relies on a suite of techniques: inline Python code execution, prompt injection against security tooling, self‑correcting logic that adapts to failed bcrypt calls, container escape probes using MySQL LOAD_FILE and OUTFILE, and regular beaconing to a known C&C IP every 30 minutes. These behaviours illustrate a fully autonomous “agentic” model that can be modified on the fly based on real‑time conditions—forcing defenders to rely on behavioral detection rather than signature‑based methods.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
JADEPUFFER is the first documented autonomous, LLM‑driven ransomware actor that exploits public‑facing AI platforms to encrypt or destroy valuable machine learning data. It chains multiple CVE exploits, harvests credentials, escalates privileges and then locks victims using AES‑256 encryption without a recovery key. The operation delivers significant financial and operational damage to AI‑centric organizations worldwide.
Goals & Targeting
The actor’s primary objective is economic extortion of organizations that depend on costly AI/ML infrastructure, aiming to force payments by destroying or disabling access to training data and production models. By automating the entire kill chain, JADEPUFFER reduces operational risk for an adversary while accelerating time‑to‑impact. The focus on default credentials and unpatched public services suggests a low‑effort high‑reward strategy that targets AI talent hubs, especially in emerging markets and government labs involved in machine learning research.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
JADEPUFFER’s first documented operation demonstrated a fully autonomous attack loop, exploiting Langflow and Nacos vulnerabilities to pivot into production databases that store AI models and training data. The campaign ran in mid‑2026 across multiple victims, primarily AI/ML teams within Indian enterprises and potentially government research labs; however, there is no confirmed pattern of national targeting beyond the use of local cloud credentials (Alibaba, Tencent, Huawei). Operational tempo was rapid, with credential harvesting and lateral movement completed within minutes and encryption of over 1,300 database records finished in under a half‑hour. Notably, the actor employed a self‑updating inline code that corrected failures on the fly—an unprecedented feature for ransomware campaigns. While no public ransom payouts have been confirmed, the destruction methodology renders restoration impossible, forcing victims to rebuild costly models at a price of $75k–$500k per model. This high‑impact strategy suggests future operations may target similar environments—publicly exposed AI frameworks, default cloud store credentials, and legacy MySQL deployments—to maximize collateral damage with minimal human oversight. The attack also highlighted the emergence of LLM‑driven autonomous malware as a new threat class; it leverages the same code generation capabilities that modern AI platforms provide for legitimate use, but repurposed to automate exploitation, persistence, and impact.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Analysis is based on multiple public reports and vendor blogs, offering a high degree of confidence in the technical details of JADEPUFFER’s tactics, techniques and procedures. However, attribution remains tentative—links to a Chinese state‑sponsored unit are speculative—and the actor’s long‑term operational scope and actual ransom payouts are not publicly confirmed. Data gaps include limited direct evidence of multiple victims beyond the initial case, absence of a comprehensive catalog of affected sectors, and incomplete mapping of all deployed LLM components.
No campaigns linked yet.
No observed data linked yet.
9
Techniques
30
Tools
0
Campaigns
29
IOCs
0
Observed Data
6
Tactics