AI Agents Now Run Ransomware Attacks End-to-End Without Human Operatorsnew
SOCRadar documented JADEPUFFER, an AI agent that autonomously executed a ransomware campaign from Langflow exploit through encryption and extortion.
SOCRadar researchers tracked JADEPUFFER, a campaign in which an AI agent planned and executed ransomware without evidence of human approval, entering through CVE-2025-3248, a missing-authentication flaw in Langflow's code-validation endpoint allowing unauthenticated Python execution. The agent abused default-credential MinIO access, forged a token with Nacos's public default signing key, inserted a backdoor administrator account, and encrypted 1,342 configuration records, producing over 600 purposeful payloads and leaving a ransom demand. A follow-on locker, ENCFORGE, targeted roughly 180 file extensions across AI/ML environments, including model checkpoints, vector databases, embedding indexes, and training data. An IoC table attributes the activity to the Lynx/INC Ransomware Group, lists C2 at 45.131.66.106, and links CVE-2026-24858 to the related FortiBleed 14-agent framework campaign.