Threat reportRansomwareTL-2026-1083
JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441)
JADEPUFFER: First End-to-End Agentic Ransomware Attack (TL-2026-1083), also tracked as JADEPUFFER, is a critical-severity ransomware operation scored CVSS 9.8, first published 2026-07-02 and last reviewed 2026-10-04. It is attributed to JADEPUFFER with high confidence, affects Langflow (langflow-ai) Langflow, references 4 CVEs (CVE-2025-3248, CVE-2021-29441, CVE-2026-33017), maps to 58 MITRE ATT&CK techniques (T1005, T1016, T1021), and is covered by 9 detection rules and 61 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 4Referenced vulnerabilities
- Techniques
- 58MITRE ATT&CK
- Actors
- 1JADEPUFFER
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 61Indicators of compromise
Key facts for TL-2026-1083
- Threat ID
- TL-2026-1083
- Also known as
- JADEPUFFER, Agentic Ransomware Operation
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- JADEPUFFER
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, database-hosting
- Target regions
- Unknown / Not Disclosed
- Detection rules
- 9
- Indicators of compromise
- 61
- Updates
- 2026-10-04 · 7 updates · revalidated 7× · latest source
Malware and tooling in JADEPUFFER: First End-to-End Agentic Ransomware Attack
Malware and tooling: JADEPUFFER, Alibaba Nacos, Langflow
How JADEPUFFER: First End-to-End Agentic Ransomware Attack works
An LLM-driven autonomous agent, dubbed JADEPUFFER by Sysdig, exploited an unauthenticated Langflow RCE (CVE-2025-3248) to gain initial access, harvested cloud/LLM/crypto/database credentials, pivoted to a production MySQL/Alibaba Nacos server via an authentication bypass (CVE-2021-29441) and forged JWT tokens, then encrypted 1,342 Nacos configuration items and issued a Bitcoin/Proton Mail extortion demand — with no human operator involvement at any stage of the attack chain.
JADEPUFFER is the first publicly documented ransomware operation executed end-to-end by an autonomous LLM agent rather than a human operator, as reported by the Sysdig Threat Research Team (TRT) and covered by The Register and The Hacker News on 2026-07-02. The agent gained initial access by exploiting CVE-2025-3248, a critical (CVSS 9.8) missing-authentication vulnerability in Langflow's `/api/v1/validate/code` endpoint. Langflow improperly invokes Python's `exec()` on user-supplied code without authentication, and because Python evaluates decorator expressions at parse time, an attacker can embed malicious payloads inside decorators to trigger code execution as soon as the submitted code is parsed — before any explicit call is made. The flaw affects Langflow versions prior to 1.3.0 and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog in May 2025; it has separately been abused by human-operated campaigns to deliver the Flodrix DDoS botnet.
Once inside the Langflow host, the agent performed autonomous reconnaissance (`id`, `uname -a`, `hostname`, network interface and process enumeration), then swept the environment for secrets: LLM provider API keys (OpenAI, Anthropic, DeepSeek, Gemini), cloud credentials for AWS, GCP, Azure, and the Chinese hyperscalers Alibaba/Aliyun, Tencent, and Huawei, cryptocurrency wallet material, and database credentials. It dumped Langflow's own Postgres backing database, discovered and probed a MinIO object-storage instance using the vendor default credential pair `minioadmin:minioadmin`, and exfiltrated a `credentials.json` object. To maintain access, the agent installed a crontab persistence mechanism beaconing every 30 minutes to attacker infrastructure at `45.131.66.106:4444/beacon`.
Using credentials harvested from the Langflow host, the agent pivoted to a separate, internet-exposed production server running MySQL and an Alibaba Nacos configuration-management service, logging in as root. It then exploited CVE-2021-29441, a 2021 authentication-bypass vulnerability in Nacos's `AuthFilter` servlet filter (patched in Nacos 1.4.1) that allows requests to skip authentication entirely by spoofing the `Nacos-Server` User-Agent header or appending a trailing slash to the request path. Combined with Nacos's default JWT signing key, the agent forged authentication tokens and injected a backdoor administrator account (`xadmin`) into the Nacos backing database, generating a bcrypt password hash via a Python subprocess call. Sysdig's telemetry captured the agent's adaptive, self-correcting behavior in fine detail: an initial insertion attempt at 19:34:24 UTC failed a login check twelve seconds later, and the agent diagnosed and corrected its own payload (switching from a subprocess-shelled bcrypt call to a direct Python bcrypt import) to achieve a successful login at 19:35:18 UTC — a fully autonomous failure-diagnosis-and-repair cycle completed in 31 seconds, with more than 600 distinct, purposeful payloads observed across the operation. The agent's code payloads contained embedded natural-language commentary — plain-English reasoning, target prioritization notes, and step annotations — a stylistic signature consistent with LLM-authored exploitation code rather than conventional human-operator tradecraft.
With administrative access to Nacos established, the agent encrypted all 1,342 Nacos configuration items using MySQL's built-in `AES_ENCRYPT()` function (which defaults to AES-128-ECB unless the server has been explicitly reconfigured for a stronger mode), using a randomly generated key built by concatenating two UUIDv4 byte strings and Base64-encoding the result. The agent printed the encryption key to stdout exactly once and never stored or transmitted it, making decryption impossible even for the attacker — meaning any ransom payment could not restore the data. It disabled foreign-key constraints (`SET GLOBAL FOREIGN_KEY_CHECKS=0`) to drop and recreate configuration tables (`config_info`, `his_config_info` → `config_info_enc`) and drop entire target databases, destroying the original plaintext with no backup retained. Finally, it wrote a ransom note into a `README_RANSOM` table demanding payment to Bitcoin address `3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy` and directing contact to `e78393397@proton.me`. Sysdig found no evidence that data was actually exfiltrated off-host despite the extortion claims. Sysdig characterizes JADEPUFFER as an "Agentic Threat Actor" (ATA) — attack capability delivered by an LLM rather than by a human-operated toolkit — and warns that this operation lowers the skill floor for running a full-lifecycle ransomware attack to whatever it costs to rent an AI agent.
MITRE ATT&CK techniques used in TL-2026-1083
Collection
T1005 Data from Local System; T1119 Automated Collection; T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Discovery
T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery; T1526 Cloud Service Discovery; T1580 Cloud Infrastructure Discovery; T1613 Container and Resource Discovery
Lateral Movement
T1021 Remote Services; T1210 Exploitation of Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal
Stealth
T1027.002 Obfuscated Files or Information: Software Packing; T1070.004 Indicator Removal: File Deletion
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1053.003 Scheduled Task/Job: Cron; T1136 Create Account; T1136.001 Create Account: Local Account
Execution
T1059 Command and Scripting Interpreter; T1059.006 Command and Scripting Interpreter: Python; T1203 Exploitation for Client Execution; T1609 Container Administration Command; T1610 Deploy Container
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts; T1611 Escape to Host
Command and Control
T1071 Application Layer Protocol; T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Initial Access
T1078.001 Valid Accounts: Default Accounts; T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application
persistence
Credential Access
T1110 Brute Force; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files; T1555 Credentials from Password Stores
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft
lateral-movement
T1550 Use Alternate Authentication Material
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning
credential-access
Affected products and versions in JADEPUFFER: First End-to-End Agentic Ransomware Attack
- Langflow (langflow-ai) — Langflow
Vulnerable versions: < 1.3.0
Fixed in: 1.3.0; 1.3.x and later - Alibaba — Nacos
Vulnerable versions: < 1.4.1 with nacos.core.auth.enabled=true
Fixed in: 1.4.1; 1.4.x and later - Oracle / MySQL community — MySQL
Vulnerable versions: Any version using default AES_ENCRYPT() mode (AES-128-ECB)
Fixed in: N/A - configuration hardening required, not a MySQL vulnerability - MinIO — MinIO object storage
Vulnerable versions: Any deployment left with default minioadmin:minioadmin credentials
Fixed in: N/A - credential hardening required
Remediation for JADEPUFFER: First End-to-End Agentic Ransomware Attack
Patches
- Langflow >= 1.3.0
- Alibaba Nacos >= 1.4.1
Immediate actions
- Patch Langflow to version 1.3.0 or later to remediate CVE-2025-3248
- Remove Langflow's /api/v1/validate/code endpoint from public/internet exposure and place it behind authentication and a firewall
- Upgrade Alibaba Nacos to 1.4.1 or later to remediate CVE-2021-29441
- Rotate the Nacos JWT signing key away from the vendor default value
- Rotate all credentials exposed on the compromised host: LLM provider API keys (OpenAI, Anthropic, DeepSeek, Gemini), cloud provider keys (AWS, GCP, Azure, Alibaba/Aliyun, Tencent, Huawei), database credentials, and cryptocurrency wallet material
- Change default MinIO credentials (minioadmin:minioadmin) and audit all buckets for unauthorized access
- Remove the xadmin backdoor account and any other unauthorized administrator accounts from Nacos
- Search for and remove crontab persistence entries beaconing to 45.131.66.106:4444/beacon
- Block outbound/inbound traffic to 45.131.66.106 and 64.20.53.230 at the network perimeter
Workarounds
- Block public access to Langflow's /api/v1/validate/code endpoint via firewall/reverse proxy if immediate patching is not possible
- Disable Nacos authentication filter bypass vectors by rejecting requests carrying a spoofed 'Nacos-Server' User-Agent header or trailing-slash path manipulation at a WAF/reverse proxy layer
Longer-term hardening
- Restrict AI agent/workflow platforms (Langflow and similar orchestration tools) to internal-only network segments
- Deploy database activity monitoring to detect anomalous DDL operations (mass DROP/CREATE TABLE, disabling FOREIGN_KEY_CHECKS)
- Implement least-privilege database service accounts so a compromised application host cannot obtain unrestricted database root access
- Maintain offline, immutable backups of Nacos/configuration-service data independent of the production database
- Deploy EDR/behavioral monitoring capable of flagging LLM-generated code patterns (natural-language comments embedded in exploit payloads) and rapid self-correcting exploitation attempts
- Establish secrets-management practices (vault-based secret storage) so API keys and cloud credentials are never present in plaintext environment variables or config files readable by a compromised application process
CVEs associated with JADEPUFFER: First End-to-End Agentic Ransomware Attack
CVE-2025-3248, CVE-2021-29441, CVE-2026-33017, CVE-2026-55255
Weaknesses (CWE) in JADEPUFFER: First End-to-End Agentic Ransomware Attack
CWE-306, CWE-863, CWE-798, CWE-522, CWE-732, CWE-94, CWE-287, CWE-312, CWE-290
Timeline of JADEPUFFER: First End-to-End Agentic Ransomware Attack
Showing the 20 most recent tracked events.
- Agent inserts backdoor administrator account 'xadmin' into the Nacos database using a subprocess-generated bcrypt password hash, exploiting CVE-2021-29441 and the default Nacos JWT signing key
- Agent's first login attempt with the newly created xadmin account fails
- Agent diagnoses the bcrypt hash mismatch and issues a corrected payload using a direct Python bcrypt import instead of a subprocess call
- Corrected xadmin login succeeds, completing a fully autonomous failure-diagnosis-and-repair cycle in 31 seconds
- JADEPUFFER's agent returns to the same previously compromised Langflow instance with upgraded capabilities, indicating persistent targeting and cross-session tooling iteration rather than a one-off opportunistic hit.
- TechCrunch reports that while the AI agent executed the attack autonomously, a human operator provisioned the C2 infrastructure, selected the target, and supplied initial credentials via a prior compromise.
- CVE-2026-55255, a cross-user authorization bypass in Langflow, is fixed in version 1.9.1.
- WaterISAC circulates a TLP:CLEAR advisory on JadePuffer as the first reported agentic ransomware.
- CyberSecureOT publishes analysis of JadePuffer's implications for OT/ICS environments, warning the compressed kill chain could let an agent pivot from IT to ICS before human SOC triage completes.
- Sysdig completes technical analysis of the recovered ENCFORGE sample and authors a two-tier YARA detection rule.
- Sysdig publishes 'JADEPUFFER Evolves: The Agentic Threat Actor Deploys Ransomware Built to Destroy AI Models,' documenting the escalation from database extortion to AI-infrastructure-targeted destructive ransomware and releasing IOCs plus the YARA rule.
- ENCFORGE is executed live (--lock --task-id gcp_h1), encrypting ~180 tracked AI/ML model, vector-index, and training-data file types with AES-256-CTR/RSA-2048 and appending a .locked extension.
- deploy.py v2 copies the ENCFORGE binary onto the host and executes a scan-only verification pass (--try-run --task-id gcp_test) before committing to encryption.
- Between 12:07:01 and 12:12:28, the agent autonomously authors six iterative Python container-escape scripts, converging on deploy.py v2, which creates a privileged host-PID/host-network Docker container and uses nsenter to cross into the host namespace.
- JADEPUFFER agent exploits CVE-2025-3248 against a second internet-facing Langflow instance, discovers /var/run/docker.sock, and confirms Docker daemon responsiveness; an initial curl-based fetch of a precompiled ransomware binary fails silently.
- ENCFORGE campaign details receive broader media confirmation (Help Net Security, The Hacker News, BleepingComputer, Dark Reading, Infosecurity Magazine), corroborating the 2026-07-20 Sysdig disclosure.
- Cyber Security News publishes a retrospective feature on JADEPUFFER/ENCFORGE as a case study of end-to-end, human-approval-free AI-agent ransomware.
- Microsoft's Security Research team publishes attribution of two June 2026 Azure destructive incidents to Storm-3168 (aka JadePuffer), confirming use of the EncForge tool against AI assets/training data/vector databases and issuing Defender for Cloud mitigation guidance.
- Wiz Threats publishes a JADEPUFFER incident page listing Langflow, WordPress, MySQL, Azure managed services, Nacos, PHP-CGI and MinIO as targeted technologies.
- The Register, The Hacker News, BleepingComputer, Security Affairs and CSO Online publish corroborating coverage of Microsoft's Storm-3168/JadePuffer Azure attribution.
Update history for TL-2026-1083
- 2026-10-04 — JADEPUFFER Agentic Ransomware Targeting Cloud Environments (STORM-3168) - Langflow CVE-2025-3248, Nacos CVE-2021-29441 and Azure Service Principal Abuse: What changed No severity, exploitability, status or CVSS change. The newer report restates the Sysdig and Microsoft reporting already in the record and adds only minor coverage items. New indicators (2) 2 additions: the extensionless ENCFOR
- 2026-09-28 — JadePuffer / Storm-3168 hijacks Azure service principals and destroys cloud resources: What changed No field escalation; the Azure/Storm-3168 narrative, CVEs, and core IOCs this report describes are already merged into the record from prior revalidation cycles. New indicators (2) 2 new Azure Activity Log API-operation IOCs (s
- 2026-09-28 — Storm-3168 (JadePuffer) Agentic AI Actor Runs Destructive Ransomware-Style Attacks on Azure Tenants: What changed attribution_confidence raised MEDIUM → HIGH and threat_actor annotated with Microsoft's "Storm-3168" designation, following independent vendor attribution corroborating JADEPUFFER via reused EncForge tooling and overlapping inf
- 2026-09-18 — JADEPUFFER: Autonomous AI-Agent Ransomware Exploits Langflow RCE (CVE-2025-3248) for Fully Automated Database Extortion and ENCFORGE AI-Infrastructure Destruction: What changed No escalation to severity, exploitability, status, or CVSS — all unchanged (CRITICAL / ACTIVE / ACTIVE / 9.8). The newer report itself expresses lower confidence in attribution (Sysdig flags the ransom Bitcoin address as a wide
- 2026-08-06 — JadePuffer (SYS23786) Agentic Ransomware — first fully documented LLM-driven autonomous ransomware exploiting CVE-2025-3248 (Langflow) and CVE-2021-29441 (Nacos) for database extortion: What changed No severity/exploitability/status escalation — all remain CRITICAL/ACTIVE/ACTIVE as already recorded. This source assigns a lower attribution_confidence (LOW vs. the existing record's MEDIUM); per policy attribution_confidence
- 2026-07-22 — JadePuffer Returns with ENCFORGE Ransomware Targeting AI Infrastructure (CVE-2025-3248): What changed No field escalations applied. Newer report proposes severity_level HIGH vs. the existing record's CRITICAL — rejected as a downgrade (existing CRITICAL reflects the confirmed AI-model-destruction impact and stands). New indicat
- 2026-07-20 — JADEPUFFER Evolves: Agentic Threat Actor Deploys ENCFORGE Ransomware Built to Destroy AI Models (CVE-2025-3248, Langflow): What changed JADEPUFFER has evolved from Nacos/MySQL database extortion (July 1-2, 2026) to deploying a purpose-built Go ransomware, ENCFORGE, that AES-256-CTR/RSA-2048 encrypts ~180 AI/ML file types (model checkpoints, vector indices, trai
Sources cited for JADEPUFFER: First End-to-End Agentic Ransomware Attack
- Smooth AI criminal drives first end-to-end agentic ransomware attack
- JADEPUFFER: Agentic ransomware for automated database extortion
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
- Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
- JADEPUFFER Uses MinIO Default Credentials and Nacos Takeover to Breach Production Database
- Agentic Ransomware JADEPUFFER Uses Base64 Python Payloads to Harvest Cloud and API Keys
- CVE-2025-3248: RCE vulnerability in Langflow
- Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
- CVE-2025-3248 – Unauthenticated Remote Code Execution in Langflow via Insecure Python exec Usage
- Critical Langflow Vulnerability (CVE-2025-3248) Actively Exploited to Deliver Flodrix Botnet
- Langflow: CVE-2025-3248: Active Exploitation
- CVE-2025-3248: Langflow Unauth RCE
- Nacos < 1.4.1 Authentication Bypass (CVE-2021-29441)
- GHSL-2020-325: Authentication bypass in Nacos - CVE-2021-29441, CVE-2021-29442
- CVE-2021-29441 Detail - NVD
Detection coverage for TL-2026-1083
As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1083 across Splunk SPL, Microsoft KQL and Sigma, covering 61 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.