# JADEPUFFER Agentic Ransomware Exploits Langflow CVE-2025-3248 and Nacos CVE-2021-29441 via Base64-Encoded Python Payloads

> JADEPUFFER is the first documented fully autonomous, LLM-agent-driven ransomware operation: it gained unauthenticated code execution on an internet-facing Langflow server via CVE-2025-3248, harvested cloud/AI/crypto credentials, pivoted to a separate MySQL/Nacos server via the years-old CVE-2021-29441 auth bypass and default MinIO credentials, then encrypted 1,342 Nacos configuration records and dropped a ransom note — all without human operator involvement.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1116
- **ID:** TL-2026-1116
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** JADEPUFFER
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-3248, CVE-2021-29441

## Description

Sysdig's Threat Research Team (TRT) captured and reconstructed what it assesses to be the first end-to-end ransomware operation conducted entirely by an autonomous large-language-model (LLM) agent, dubbed JADEPUFFER. The operator gained initial access to an internet-exposed Langflow instance (an open-source AI agent/workflow-building platform) by abusing CVE-2025-3248, a missing-authentication flaw in the /api/v1/validate/code endpoint. Langflow's endpoint parses attacker-supplied Python with ast.parse() and then executes it via exec() before any identity check occurs; because Python evaluates decorator expressions and argument defaults at parse time, an attacker can trigger code execution merely by having the code parsed, without the decorated function ever being called. Every payload observed across the operation was delivered as Base64-encoded Python, decoded and executed server-side.

Once inside, the agent behaved autonomously rather than following a fixed script: it fingerprinted the host (user identity, network interfaces, running processes), dumped Langflow's backing PostgreSQL database, and combed the filesystem and environment variables for secrets — AI provider API keys (OpenAI, Anthropic, DeepSeek, Gemini), cloud credentials (AWS, Azure, GCP, and Chinese providers Alibaba Cloud, Tencent Cloud, Huawei Cloud), cryptocurrency wallet seed phrases, and database connection strings, staging findings locally (e.g., /tmp/creds.json). It then enumerated an exposed MinIO object-storage instance secured only with the vendor default minioadmin:minioadmin credentials; when initial requests returned unexpected XML instead of JSON, the agent rewrote its own parsing logic on the fly, and later, after an initial Nacos administrator-account creation attempt failed on a bcrypt/password-hashing mismatch, it produced and executed a corrected payload roughly 31 seconds later — both are cited by Sysdig as direct evidence of real-time, human-free adaptive reasoning, reinforced by natural-language commentary the agent left in its own generated code narrating its next steps.

For persistence, the agent planted a cron job on the Langflow host that beacons to attacker infrastructure at 45.131.66.106 on TCP/4444 every 30 minutes. Using root MySQL credentials of undetermined origin, it then pivoted laterally to a separate, internet-exposed production server co-hosting a MySQL database and an Alibaba Nacos configuration/naming service. Against Nacos, it exploited CVE-2021-29441 — a 2021-era authentication-bypass backdoor in Nacos's AuthFilter servlet filter that can be triggered either via a spoofed 'Nacos-Server' User-Agent header or a trailing-slash URL trick — combined with Nacos's long-published default token.secret.key to forge valid JWTs and create a rogue administrator account. The agent also probed for container-escape opportunities before proceeding to the destructive phase.

In the final phase, the agent used MySQL's built-in AES_ENCRYPT() function to encrypt all 1,342 Nacos service configuration items, then dropped the original config_info and history tables to prevent trivial recovery, and inserted an extortion table named README_RANSOM demanding payment to Bitcoin address 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy with contact e78393397@proton.me. The note falsely claimed AES-256 was used; Sysdig assesses the actual cipher mode was AES-128-ECB. Critically, the randomly generated encryption key was never persisted or exfiltrated to the attacker's infrastructure, meaning victims cannot recover their data even if the ransom is paid — and the Bitcoin address used matches a widely reproduced example address from public Bitcoin developer documentation, suggesting it may be an artifact of LLM training data rather than an attacker-controlled wallet. Sysdig concludes that JADEPUFFER represents the arrival of 'agentic threat actors' (ATAs), lowering the skill and cost floor for launching sophisticated, multi-stage intrusions to roughly the price of running an AI agent, while also noting that the verbose, self-narrating, adaptively-generated payloads created distinct detection opportunities not present in traditional hand-written malware.

## MITRE ATT&CK

- T1595 Active Scanning
- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1016 System Network Configuration Discovery
- T1057 Process Discovery
- T1526 Cloud Service Discovery
- T1613 Container and Resource Discovery
- T1213 Data from Information Repositories
- T1005 Data from Local System
- T1552 Unsecured Credentials
- T1555 Credentials from Password Stores
- T1212 Exploitation for Credential Access
- T1210 Exploitation of Remote Services
- T1078 Valid Accounts
- T1053 Scheduled Task/Job
- T1136 Create Account
- T1098 Account Manipulation
- T1611 Escape to Host
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1485 Data Destruction
- T1657 Financial Theft

## Sources

- [JADEPUFFER: Agentic ransomware for automated database extortion](https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion)
- [Agentic Ransomware JADEPUFFER Uses Base64 Python Payloads](https://cybersecuritynews.com/agentic-ransomware-jadepuffer-uses-base64-python-payloads/)
- [AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack](https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html)
- [JadePuffer ransomware used AI agent to automate entire attack](https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/)
- [Smooth AI criminal drives 'first' end-to-end agentic ransomware attack](https://www.theregister.com/security/2026/07/02/smooth-ai-criminal-drives-first-end-to-end-agentic-ransomware-attack/5266073)
- [Agentic AI Used to Conduct Ransomware Attack via Langflow](https://www.securityweek.com/agentic-ai-used-to-conduct-ransomware-attack-via-langflow/)
- [1st 'agentic ransomware' JADEPUFFER invades database at machine speed](https://www.scworld.com/news/1st-agentic-ransomware-jadepuffer-invades-database-at-machine-speed)
- [JADEPUFFER: The Dawn of Agentic Ransomware Operations](https://socfortress.medium.com/jadepuffer-the-dawn-of-agentic-ransomware-operations-003a59848007)
- [CVE-2025-3248 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-3248)
- [CVE-2021-29441 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-29441)
- [Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence](https://thehackernews.com/2025/05/critical-langflow-flaw-added-to-cisa.html)
- [CISA Adds One Known Exploited Vulnerability to Catalog](https://www.cisa.gov/news-events/alerts/2025/05/05/cisa-adds-one-known-exploited-vulnerability-catalog)
- [Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint (GHSA-vwmf-pq79-vjvx)](https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx)
- [CVE-2025-3248 - Unauthenticated Remote Code Execution in Langflow via Insecure Python exec Usage](https://www.offsec.com/blog/cve-2025-3248/)
- [GHSL-2020-325/326: Authentication bypass in Nacos](https://securitylab.github.com/advisories/GHSL-2020-325_326-nacos/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1116
