# JADEPUFFER

> As of 2026-10-04, JADEPUFFER is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning ransomware. ATT&CK coverage spans 66 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1016 (System Network Configuration Discovery), T1041 (Exfiltration Over C2 Channel).

- **Tracked threats:** 3
- **Categories:** RANSOMWARE
- **As of:** 2026-10-04

## ATT&CK techniques observed

66 techniques observed across 3 of 3 tracked threats. Tactics: Discovery (10), Credential Access (9), Stealth (formerly Defense Evasion) (8), Impact (6), Execution (5), Persistence (5).

- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 3 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 3 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 3 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 3 of 3 tracked threats
- [T1210](https://intel.threadlinqs.com/technique/T1210) Exploitation of Remote Services — Lateral Movement — observed in 3 of 3 tracked threats
- [T1213](https://intel.threadlinqs.com/technique/T1213) Data from Information Repositories — Collection — observed in 3 of 3 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 3 of 3 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 3 of 3 tracked threats
- [T1526](https://intel.threadlinqs.com/technique/T1526) Cloud Service Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 3 of 3 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 2 of 3 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats

## Tracked threats

- [JADEPUFFER Agentic Ransomware Exploits Langflow CVE-2025-3248 and Nacos CVE-2021-29441 via Base64-Encoded Python Payloads](https://intel.threadlinqs.com/threat/TL-2026-1116) — CRITICAL
- [JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441)](https://intel.threadlinqs.com/threat/TL-2026-1083) — CRITICAL
- [JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248) and Nacos Auth Bypass (CVE-2021-29441)](https://intel.threadlinqs.com/threat/TL-2026-1044) — CRITICAL

## Related CVEs

4 CVEs referenced by tracked JADEPUFFER activity.

- [CVE-2026-55255](https://intel.threadlinqs.com/cve/CVE-2026-55255)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/JADEPUFFER
