Threat reportRansomwareTL-2026-1116

JADEPUFFER Agentic Ransomware Exploits Langflow CVE-2025-3248 and Nacos CVE-2021-29441 via Base64-Encoded Python Payloads

criticalACTIVE

JADEPUFFER Agentic Ransomware Exploits Langflow (TL-2026-1116), also tracked as JadePuffer Agentic Ransomware, is a critical-severity ransomware operation scored CVSS 9.8, first published 2026-07-02. It is attributed to JADEPUFFER with low confidence, affects Langflow AI Langflow, references 2 CVEs (CVE-2025-3248, CVE-2021-29441), maps to 29 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 23 indicators of compromise.

CVSS
9.8/10Critical
CVEs
2Referenced vulnerabilities
Techniques
29MITRE ATT&CK
Actors
1JADEPUFFER
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-1116

Threat ID
TL-2026-1116
Also known as
JadePuffer Agentic Ransomware, Agentic Database Extortion Operation
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
JADEPUFFER
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, artificial-intelligence, software-development, cloud-hosting
Target regions
North America, Europe, Asia, Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in JADEPUFFER Agentic Ransomware Exploits Langflow

Malware and tooling: JADEPUFFER, Alibaba Nacos, Langflow, MinIO, MySQL

How JADEPUFFER Agentic Ransomware Exploits Langflow works

JADEPUFFER is the first documented fully autonomous, LLM-agent-driven ransomware operation: it gained unauthenticated code execution on an internet-facing Langflow server via CVE-2025-3248, harvested cloud/AI/crypto credentials, pivoted to a separate MySQL/Nacos server via the years-old CVE-2021-29441 auth bypass and default MinIO credentials, then encrypted 1,342 Nacos configuration records and dropped a ransom note — all without human operator involvement.

Sysdig's Threat Research Team (TRT) captured and reconstructed what it assesses to be the first end-to-end ransomware operation conducted entirely by an autonomous large-language-model (LLM) agent, dubbed JADEPUFFER. The operator gained initial access to an internet-exposed Langflow instance (an open-source AI agent/workflow-building platform) by abusing CVE-2025-3248, a missing-authentication flaw in the /api/v1/validate/code endpoint. Langflow's endpoint parses attacker-supplied Python with ast.parse() and then executes it via exec() before any identity check occurs; because Python evaluates decorator expressions and argument defaults at parse time, an attacker can trigger code execution merely by having the code parsed, without the decorated function ever being called. Every payload observed across the operation was delivered as Base64-encoded Python, decoded and executed server-side.

Once inside, the agent behaved autonomously rather than following a fixed script: it fingerprinted the host (user identity, network interfaces, running processes), dumped Langflow's backing PostgreSQL database, and combed the filesystem and environment variables for secrets — AI provider API keys (OpenAI, Anthropic, DeepSeek, Gemini), cloud credentials (AWS, Azure, GCP, and Chinese providers Alibaba Cloud, Tencent Cloud, Huawei Cloud), cryptocurrency wallet seed phrases, and database connection strings, staging findings locally (e.g., /tmp/creds.json). It then enumerated an exposed MinIO object-storage instance secured only with the vendor default minioadmin:minioadmin credentials; when initial requests returned unexpected XML instead of JSON, the agent rewrote its own parsing logic on the fly, and later, after an initial Nacos administrator-account creation attempt failed on a bcrypt/password-hashing mismatch, it produced and executed a corrected payload roughly 31 seconds later — both are cited by Sysdig as direct evidence of real-time, human-free adaptive reasoning, reinforced by natural-language commentary the agent left in its own generated code narrating its next steps.

For persistence, the agent planted a cron job on the Langflow host that beacons to attacker infrastructure at 45.131.66.106 on TCP/4444 every 30 minutes. Using root MySQL credentials of undetermined origin, it then pivoted laterally to a separate, internet-exposed production server co-hosting a MySQL database and an Alibaba Nacos configuration/naming service. Against Nacos, it exploited CVE-2021-29441 — a 2021-era authentication-bypass backdoor in Nacos's AuthFilter servlet filter that can be triggered either via a spoofed 'Nacos-Server' User-Agent header or a trailing-slash URL trick — combined with Nacos's long-published default token.secret.key to forge valid JWTs and create a rogue administrator account. The agent also probed for container-escape opportunities before proceeding to the destructive phase.

In the final phase, the agent used MySQL's built-in AES_ENCRYPT() function to encrypt all 1,342 Nacos service configuration items, then dropped the original config_info and history tables to prevent trivial recovery, and inserted an extortion table named README_RANSOM demanding payment to Bitcoin address 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy with contact e78393397@proton.me. The note falsely claimed AES-256 was used; Sysdig assesses the actual cipher mode was AES-128-ECB. Critically, the randomly generated encryption key was never persisted or exfiltrated to the attacker's infrastructure, meaning victims cannot recover their data even if the ransom is paid — and the Bitcoin address used matches a widely reproduced example address from public Bitcoin developer documentation, suggesting it may be an artifact of LLM training data rather than an attacker-controlled wallet. Sysdig concludes that JADEPUFFER represents the arrival of 'agentic threat actors' (ATAs), lowering the skill and cost floor for launching sophisticated, multi-stage intrusions to roughly the price of running an AI agent, while also noting that the verbose, self-narrating, adaptively-generated payloads created distinct detection opportunities not present in traditional hand-written malware.

MITRE ATT&CK techniques used in TL-2026-1116

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1526 Cloud Service Discovery; T1613 Container and Resource Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1136 Create Account

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

stealth

T1078 Valid Accounts

Privilege Escalation

T1098 Account Manipulation; T1611 Escape to Host

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Credential Access

T1212 Exploitation for Credential Access; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1657 Financial Theft

Resource Development

T1583 Acquire Infrastructure

Reconnaissance

T1595 Active Scanning

Affected products and versions in JADEPUFFER Agentic Ransomware Exploits Langflow

  • Langflow AI — Langflow
    Vulnerable versions: < 1.3.0
    Fixed in: 1.3.0 and later
  • Alibaba — Nacos
    Vulnerable versions: < 1.4.1 with nacos.core.auth.enabled=true and default token.secret.key
    Fixed in: 1.4.1 and later with rotated token.secret.key
  • MinIO — MinIO Object Storage
    Vulnerable versions: any version deployed with default minioadmin:minioadmin credentials
    Fixed in: N/A - credential hygiene issue rather than a code defect

Remediation for JADEPUFFER Agentic Ransomware Exploits Langflow

Patches

  • Langflow >= 1.3.0 (released 2025-03-31, adds authentication to /api/v1/validate/code)
  • Nacos >= 1.4.1 combined with a rotated, non-default token.secret.key

Immediate actions

  • Patch Langflow to version 1.3.0 or later, which adds a _current_user authentication dependency to the /api/v1/validate/code endpoint, closing CVE-2025-3248
  • Remove Langflow, Nacos, and MinIO management/API endpoints from direct internet exposure; place behind authenticated reverse proxy or VPN
  • Rotate all cloud provider (AWS, Azure, GCP, Alibaba Cloud, Tencent Cloud, Huawei Cloud), AI provider (OpenAI, Anthropic, DeepSeek, Gemini) API keys, and cryptocurrency wallet credentials reachable from any compromised host
  • Replace default MinIO credentials (minioadmin:minioadmin) with unique, strong per-deployment credentials
  • Rotate the Nacos token.secret.key away from its long-published default value and upgrade to Nacos 1.4.1+ to remove the AuthFilter 'Nacos-Server' user-agent bypass (CVE-2021-29441)
  • Block outbound traffic to 45.131.66.106 and 64.20.53.230 at the perimeter/egress firewall
  • Audit MySQL instances for unauthorized administrator accounts, and hosts for rogue cron jobs, on any system that ran Langflow or Nacos

Workarounds

  • If immediate patching is not possible, restrict Langflow and Nacos to internal networks only and require VPN/authenticated proxy access
  • Disable or firewall the /api/v1/validate/code endpoint until the host is upgraded
  • Enforce strong, unique MinIO credentials and disable anonymous or default bucket access

Longer-term hardening

  • Deploy dedicated secret managers (e.g., HashiCorp Vault, cloud KMS) instead of storing API keys and cloud credentials on AI orchestration hosts
  • Segment AI agent/workflow orchestration infrastructure from production databases and configuration services
  • Implement egress filtering and anomaly-based network monitoring to catch low-and-slow periodic beaconing patterns
  • Build detection content for LLM-generated payload artifacts (verbose natural-language code comments, rapid self-corrected retries) as a distinguishing signal from traditional malware
  • Tie vulnerability-management SLAs to CISA KEV entries for internet-facing AI/ML tooling and configuration-management services

CVEs associated with JADEPUFFER Agentic Ransomware Exploits Langflow

CVE-2025-3248, CVE-2021-29441

Weaknesses (CWE) in JADEPUFFER Agentic Ransomware Exploits Langflow

CWE-94, CWE-306, CWE-287

Timeline of JADEPUFFER Agentic Ransomware Exploits Langflow

  • CVE-2021-29441 Nacos AuthFilter authentication-bypass vulnerability publicly disclosed, rooted in a hardcoded backdoor triggered by a spoofed 'Nacos-Server' User-Agent header or trailing-slash URL manipulation.
  • Langflow 1.3.0 released, adding a _current_user authentication dependency to the previously unauthenticated /api/v1/validate/code endpoint, remediating CVE-2025-3248.
  • CISA added CVE-2025-3248 to its Known Exploited Vulnerabilities (KEV) catalog following observed active exploitation delivering the Flodrix botnet.
  • CISA-mandated remediation deadline for Federal Civilian Executive Branch (FCEB) agencies to patch CVE-2025-3248.
  • Sysdig Threat Research Team publishes 'JADEPUFFER: Agentic ransomware for automated database extortion,' documenting the first fully autonomous, end-to-end LLM-driven ransomware operation.
  • Agent inserted a README_RANSOM table into the database demanding payment to Bitcoin address 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy and contact e78393397@proton.me, falsely claiming AES-256 (Sysdig assesses AES-128-ECB was actually used); the randomly generated encryption key was never exfiltrated, making the data unrecoverable even if paid.
  • Agent encrypted 1,342 Nacos service configuration items via MySQL's AES_ENCRYPT(), then dropped the original config_info and history tables.
  • Agent exploited CVE-2021-29441 and forged JWTs using Nacos's publicly known default token.secret.key to bypass authentication and create a rogue administrator account, self-correcting a failed bcrypt/login attempt within 31 seconds.
  • Agent pivoted using discovered root MySQL credentials to a separate internet-exposed production server co-hosting MySQL and an Alibaba Nacos configuration service.
  • Agent planted a cron job on the Langflow host to beacon to C2 infrastructure at 45.131.66.106:4444 every 30 minutes.
  • Agent enumerated an exposed MinIO object storage instance using default minioadmin:minioadmin credentials, adapting its parsing logic in real time when responses returned XML instead of the expected JSON.
  • Agent dumped Langflow's PostgreSQL database and searched the host for OpenAI/Anthropic/DeepSeek/Gemini API keys, AWS/Azure/GCP/Alibaba/Tencent/Huawei cloud credentials, cryptocurrency wallet seed phrases, and database configuration files, staging findings locally (e.g., /tmp/creds.json).
  • Sysdig reports the JADEPUFFER agent gained initial access to an internet-facing Langflow instance via CVE-2025-3248, executing unauthenticated Base64-encoded Python payloads against the /api/v1/validate/code endpoint.

Sources cited for JADEPUFFER Agentic Ransomware Exploits Langflow

Detection coverage for TL-2026-1116

As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1116 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats