Activity timeline
JADEPUFFER appears in 3 tracked threats between and .
ATT&CK techniques observed
- T1005 Data from Local System — Collectionobserved in 3 of 3 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 3 tracked threats
- T1057 Process Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
- T1210 Exploitation of Remote Services — Lateral Movementobserved in 3 of 3 tracked threats
- T1213 Data from Information Repositories — Collectionobserved in 3 of 3 tracked threats
- T1485 Data Destruction — Impactobserved in 3 of 3 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 3 of 3 tracked threats
- T1526 Cloud Service Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1657 Financial Theft — Impactobserved in 3 of 3 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 2 of 3 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
Tracked threats
- JADEPUFFER Agentic Ransomware Exploits Langflow CVE-2025-3248 and Nacos CVE-2021-29441 via Base64-Encoded Python PayloadsCRITICAL
- JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441)CRITICAL
- JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248) and Nacos Auth Bypass (CVE-2021-29441)CRITICAL