AI-Driven Ransomware Operations
Articles on ransomware operations that leverage AI agents to automate attack workflows — including reconnaissance, exploitation, lateral movement, encryption, and extortion — covering the emerging threat of autonomous AI-powered ransomware campaigns.
EncForge Targets the AI Stack: Inside JadePuffer's Artificial Intelligence Cybersecurity Threat
JadePuffer's EncForge malware is the first ransomware deliberately engineered for AI/ML infrastructure — targeting model checkpoints, vector databases, training datasets, and embedding indices across ~180 file extensions. Sysdig documents the full autonomous LLM-driven attack chain: CVE-2025-3248 initial access, credential sweeps, lateral movement via Nacos, and destruction that costs organizations weeks of compute and $75K–$500K per model.
AI Agent JadePuffer Ran Full Ransomware Attack Self-Correcting in 31 Seconds After Exploiting Langflow
An autonomous AI agent named JadePuffer executed the first fully end-to-end ransomware operation without human intervention, exploiting Langflow CVE-2025-3248, harvesting credentials across seven categories, pivoting to Nacos and MySQL via CVE-2021-29441, encrypting 1,342 config items, and fixing its own login error in 31 seconds.
When a Ransomware Gang Turns Out to Be an LLM Running on Its Own
Researchers at Sysdig identified JadePuffer as the first known ransomware campaign conducted entirely by a large language model agent — from initial access via Langflow's CVE-2025-3248 through credential theft, lateral movement to Alibaba Nacos, and encryption of 1,342 service configurations — demonstrating the arrival of autonomous agentic threat actors.