{"id":777172,"date":"2026-07-03T07:24:14","date_gmt":"2026-07-03T07:24:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/777172\/"},"modified":"2026-07-03T07:24:14","modified_gmt":"2026-07-03T07:24:14","slug":"smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/777172\/","title":{"rendered":"Smooth AI criminal drives &#8216;first&#8217; end-to-end agentic ransomware attack"},"content":{"rendered":"<p class=\"kicker \" style=\"\">Security<\/p>\n<p class=\"subtitle \" style=\"\">Don&#8217;t count on the LLM to return your data &#8211; even if you pay up<\/p>\n<p>They&#8217;re not bad; they&#8217;re just prompted that way. Sysdig threat hunters documented what they say is the first-ever documented agentic ransomware infection with an LLM &#8211; not a human &#8211; driving the entire extortion operation, from gaining initial access to compromising a production database server and destroying data.<\/p>\n<p>The security shop\u2019s research team named the agentic intruder JadePuffer and said it gained initial access to an internet-facing Langflow instance by exploiting <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-3248\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2025-3248<\/a>, and then ran a fully automated attack.<\/p>\n<p>\u201cThe most striking characteristic, however, was the LLM&#8217;s behavior,\u201d Sysdig director of threat research Michael Clark <a href=\"https:\/\/www.sysdig.com\/blog\/jadepuffer-agentic-ransomware-for-automated-database-extortion\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> in a blog about the agentic ransomware and extortion operation.\u00a0<\/p>\n<p>JadePuffer\u2019s \u201cself-narrating\u201d payloads \u201ccontained natural language reasoning, target prioritization, and the kind of detailed annotations that human operators don\u2019t often write but LLM-generated code produces reflexively,\u201d Clark added. \u201cThe operation also adapted in real time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds.\u201d<\/p>\n<p>After exploiting CVE-2025-3248, a missing authentication vulnerability in\u00a0<a href=\"https:\/\/github.com\/langflow-ai\/langflow\" rel=\"nofollow noopener\" target=\"_blank\">Langflow<\/a> that allows remote, unauthenticated attackers to execute arbitrary Python on the host, the AI agent began scanning for and collecting secrets, including LLM provider API keys, cloud credentials \u201cwith explicit coverage of Chinese providers\u201d including Alibaba, Aliyun, Tencent, and Huawei, while also scanning for AWS, Azure and Google Cloud Platform, cryptocurrency wallets, and database credentials.\u00a0<\/p>\n<p>The AI also installed a crontab entry on the Langflow server to maintain persistence and call back to the attacker\u2019s infrastructure every 30 minutes.<\/p>\n<p>JadePuffer\u2019s intended target was a separate internet-exposed production server running a MySQL database and an Alibaba Nacos configuration service, we\u2019re told. Nacos is an open-source service-discovery and dynamic configuration platform developed by Alibaba and used in the cloud provider\u2019s microservices applications.<\/p>\n<p>The agent connected to the server&#8217;s exposed MySQL port using root credentials, although Sysdig doesn\u2019t know how the attacker obtained them. These credentials weren\u2019t stolen from the victim\u2019s environment.<\/p>\n<p>JadePuffer then attacked Nacos via multiple vectors including an authorization bypass flaw (CVE-2021-29441) and forging a valid JSON web token (JWT) using Nacos&#8217;s default signing key. Additionally, using its root database access, the LLM injected a backdoor administrator into the Nacos backing database.<\/p>\n<p>It ultimately encrypted all 1,342 Nacos service configuration items using MySQL&#8217;s built-in AES encryption function, and created an extortion demand, ransom note, Bitcoin payment address, and a Proton Mail contact:<\/p>\n<p>&#8220;YOUR DATA HAS BEEN ENCRYPTED. All NACOS configurations, REDACTED customer data, and REDACTED PII have been encrypted with AES-256.&#8221;, &#8220;3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy&#8221;, &#8220;e78393397[@]proton[.]me&#8221;<\/p>\n<p>However, according to the threat hunters, the victim can\u2019t recover the encrypted data, even if they paid the ransom demand, because the agent escalated \u201cfrom row-level deletion to dropping entire database schemas, narrating its own targeting rationale,\u201d without backing up any of the encrypted data.\u00a0\u00a0<\/p>\n<p>There are a couple of things that security teams and vulnerability managers should do immediately to avoid being ransomed by this AI agent. First up: patch Langflow to a release that fixes CVE-2025-3248, and do not expose code-execution\/validation endpoints to the internet.<\/p>\n<p>Also, don\u2019t ever expose Nacos to the open internet, change its default token.secret.key, and upgrade to a release that forces a custom key.<\/p>\n<p>The threat hunters also recommend against running any AI orchestration servers with provider API keys or cloud credentials in their environment.<\/p>\n<p>While the AI agent didn\u2019t use any especially sophisticated or unique techniques in this attack, the fact that an LLM \u201cstrung them together into a complete ransomware operation against neglected internet-facing infrastructure,\u201d is notable, according to Clark. \u201cThe skill floor for running ransomware has dropped to whatever it costs to run an agent, and if that agent is running on stolen credentials through <a href=\"https:\/\/www.theregister.com\/security\/2026\/02\/04\/aws-intruder-pulled-off-ai-assisted-cloud-break-in-in-8-mins\/4945272\" rel=\"nofollow noopener\" target=\"_blank\">LLMjacking<\/a>, the cost to an attacker is close to zero.\u201d\u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Security Don&#8217;t count on the LLM to return your data &#8211; even if you pay up They&#8217;re not&hellip;\n","protected":false},"author":2,"featured_media":777173,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[62,276,277,49,48,61],"class_list":["post-777172","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-ca","tag-canada","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/777172","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=777172"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/777172\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/777173"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=777172"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=777172"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=777172"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}