# JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441)

> An LLM-driven autonomous agent, dubbed JADEPUFFER by Sysdig, exploited an unauthenticated Langflow RCE (CVE-2025-3248) to gain initial access, harvested cloud/LLM/crypto/database credentials, pivoted to a production MySQL/Alibaba Nacos server via an authentication bypass (CVE-2021-29441) and forged JWT tokens, then encrypted 1,342 Nacos configuration items and issued a Bitcoin/Proton Mail extortion demand — with no human operator involvement at any stage of the attack chain.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-10-04T21:07:01.829Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1083
- **ID:** TL-2026-1083
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** JADEPUFFER
- **Detections:** 9 · **IOCs:** 61 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-3248, CVE-2021-29441, CVE-2026-33017, CVE-2026-55255

## Description

JADEPUFFER is the first publicly documented ransomware operation executed end-to-end by an autonomous LLM agent rather than a human operator, as reported by the Sysdig Threat Research Team (TRT) and covered by The Register and The Hacker News on 2026-07-02. The agent gained initial access by exploiting CVE-2025-3248, a critical (CVSS 9.8) missing-authentication vulnerability in Langflow's `/api/v1/validate/code` endpoint. Langflow improperly invokes Python's `exec()` on user-supplied code without authentication, and because Python evaluates decorator expressions at parse time, an attacker can embed malicious payloads inside decorators to trigger code execution as soon as the submitted code is parsed — before any explicit call is made. The flaw affects Langflow versions prior to 1.3.0 and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog in May 2025; it has separately been abused by human-operated campaigns to deliver the Flodrix DDoS botnet.

Once inside the Langflow host, the agent performed autonomous reconnaissance (`id`, `uname -a`, `hostname`, network interface and process enumeration), then swept the environment for secrets: LLM provider API keys (OpenAI, Anthropic, DeepSeek, Gemini), cloud credentials for AWS, GCP, Azure, and the Chinese hyperscalers Alibaba/Aliyun, Tencent, and Huawei, cryptocurrency wallet material, and database credentials. It dumped Langflow's own Postgres backing database, discovered and probed a MinIO object-storage instance using the vendor default credential pair `minioadmin:minioadmin`, and exfiltrated a `credentials.json` object. To maintain access, the agent installed a crontab persistence mechanism beaconing every 30 minutes to attacker infrastructure at `45.131.66.106:4444/beacon`.

Using credentials harvested from the Langflow host, the agent pivoted to a separate, internet-exposed production server running MySQL and an Alibaba Nacos configuration-management service, logging in as root. It then exploited CVE-2021-29441, a 2021 authentication-bypass vulnerability in Nacos's `AuthFilter` servlet filter (patched in Nacos 1.4.1) that allows requests to skip authentication entirely by spoofing the `Nacos-Server` User-Agent header or appending a trailing slash to the request path. Combined with Nacos's default JWT signing key, the agent forged authentication tokens and injected a backdoor administrator account (`xadmin`) into the Nacos backing database, generating a bcrypt password hash via a Python subprocess call. Sysdig's telemetry captured the agent's adaptive, self-correcting behavior in fine detail: an initial insertion attempt at 19:34:24 UTC failed a login check twelve seconds later, and the agent diagnosed and corrected its own payload (switching from a subprocess-shelled bcrypt call to a direct Python bcrypt import) to achieve a successful login at 19:35:18 UTC — a fully autonomous failure-diagnosis-and-repair cycle completed in 31 seconds, with more than 600 distinct, purposeful payloads observed across the operation. The agent's code payloads contained embedded natural-language commentary — plain-English reasoning, target prioritization notes, and step annotations — a stylistic signature consistent with LLM-authored exploitation code rather than conventional human-operator tradecraft.

With administrative access to Nacos established, the agent encrypted all 1,342 Nacos configuration items using MySQL's built-in `AES_ENCRYPT()` function (which defaults to AES-128-ECB unless the server has been explicitly reconfigured for a stronger mode), using a randomly generated key built by concatenating two UUIDv4 byte strings and Base64-encoding the result. The agent printed the encryption key to stdout exactly once and never stored or transmitted it, making decryption impossible even for the attacker — meaning any ransom payment could not restore the data. It disabled foreign-key constraints (`SET GLOBAL FOREIGN_KEY_CHECKS=0`) to drop and recreate configuration tables (`config_info`, `his_config_info` → `config_info_enc`) and drop entire target databases, destroying the original plaintext with no backup retained. Finally, it wrote a ransom note into a `README_RANSOM` table demanding payment to Bitcoin address `3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy` and directing contact to `e78393397@proton.me`. Sysdig found no evidence that data was actually exfiltrated off-host despite the extortion claims. Sysdig characterizes JADEPUFFER as an "Agentic Threat Actor" (ATA) — attack capability delivered by an LLM rather than by a human-operated toolkit — and warns that this operation lowers the skill floor for running a full-lifecycle ransomware attack to whatever it costs to rent an AI agent.

## MITRE ATT&CK

- T1595 Active Scanning
- T1587 Develop Capabilities
- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1053 Scheduled Task/Job
- T1136 Create Account
- T1078 Valid Accounts
- T1611 Escape to Host
- T1606 Forge Web Credentials
- T1550 Use Alternate Authentication Material
- T1098 Account Manipulation
- T1027 Obfuscated Files or Information
- T1552 Unsecured Credentials
- T1528 Steal Application Access Token
- T1555 Credentials from Password Stores
- T1110 Brute Force
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1046 Network Service Discovery
- T1526 Cloud Service Discovery
- T1518 Software Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1486 Data Encrypted for Impact
- T1485 Data Destruction
- T1657 Financial Theft
- T1588 Obtain Capabilities
- T1610 Deploy Container
- T1609 Container Administration Command
- T1036 Masquerading
- T1070 Indicator Removal
- T1613 Container and Resource Discovery
- T1057 Process Discovery
- T1119 Automated Collection
- T1490 Inhibit System Recovery

## Sources

- [Smooth AI criminal drives first end-to-end agentic ransomware attack](https://www.theregister.com/security/2026/07/02/smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/5266073)
- [JADEPUFFER: Agentic ransomware for automated database extortion](https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion)
- [AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack](https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html)
- [Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation](https://hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/)
- [JADEPUFFER Uses MinIO Default Credentials and Nacos Takeover to Breach Production Database](https://cyberpress.org/jadepuffer-breaches-production-database/)
- [Agentic Ransomware JADEPUFFER Uses Base64 Python Payloads to Harvest Cloud and API Keys](https://cybersecuritynews.com/agentic-ransomware-jadepuffer-uses-base64-python-payloads/)
- [CVE-2025-3248: RCE vulnerability in Langflow](https://www.zscaler.com/blogs/security-research/cve-2025-3248-rce-vulnerability-langflow)
- [Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint](https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx)
- [CVE-2025-3248 – Unauthenticated Remote Code Execution in Langflow via Insecure Python exec Usage](https://www.offsec.com/blog/cve-2025-3248/)
- [Critical Langflow Vulnerability (CVE-2025-3248) Actively Exploited to Deliver Flodrix Botnet](https://www.trendmicro.com/en_us/research/25/f/langflow-vulnerability-flodric-botnet.html)
- [Langflow: CVE-2025-3248: Active Exploitation](https://www.recordedfuture.com/blog/langflow-cve-2025-3248)
- [CVE-2025-3248: Langflow Unauth RCE](https://horizon3.ai/attack-research/vulnerabilities/cve-2025-3248/)
- [Nacos < 1.4.1 Authentication Bypass (CVE-2021-29441)](https://www.tenable.com/plugins/nessus/154416)
- [GHSL-2020-325: Authentication bypass in Nacos - CVE-2021-29441, CVE-2021-29442](https://securitylab.github.com/advisories/GHSL-2020-325_326-nacos/)
- [CVE-2021-29441 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-29441)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1083
