Cybersecurity Researchers Identify First Fully Autonomous AI-Driven Ransomware Attack — Campus Technology

- Advertisement -


Cybersecurity Researchers Identify First Fully Autonomous AI-Driven Ransomware Attack

Threat researchers at cloud security firm Sysdig have disclosed what they describe as the first documented ransomware operation carried out end-to-end by an autonomous AI agent, with no human typing commands or directing individual steps once the attack was underway. The firm named the threat actor JADEPUFFER and published its technical analysis between July 4 and July 6.

- Advertisement -
- Advertisement -

According to Sysdig, JADEPUFFER gained initial access through an internet-facing instance of Langflow, an open source framework that developers use to build AI applications and agent workflows. The entry point was CVE-2025-3248, a missing-authentication flaw that allows an unauthenticated attacker to run arbitrary Python code on the host. The vendor patched the flaw in Langflow 1.3.0, and the Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities list in May 2025, meaning the vulnerability itself was neither new nor secret at the time of the attack.

Once inside, the agent enumerated the host and swept the environment for secrets across multiple categories at once, including application programming interface keys for OpenAI, Anthropic, DeepSeek, and Google; cloud credentials spanning Amazon Web Services, Google Cloud, Microsoft Azure, and several Chinese providers; cryptocurrency wallet seed phrases; and database credentials. It dumped Langflow’s backing Postgres database, found a MinIO object storage service still running with its factory-default credentials, and installed a crontab entry that beaconed to the attacker’s infrastructure every 30 minutes to maintain persistence. From there, it used harvested credentials to reach a separate, internet-exposed production server running MySQL and Alibaba’s Nacos configuration platform, exploiting a 2021 authentication bypass and forging a token with a default signing key publicly known since 2020.

The most notable evidence of autonomous operation, according to Sysdig, came when an early attempt to insert a backdoor administrator account into Nacos failed a login check. Thirty-one seconds later, without any human intervention, the agent diagnosed the cause as a subprocess path issue that prevented the password hash from being generated correctly, switched its method, and completed the task. The agent went on to encrypt 1,342 Nacos configuration records and leave a ransom note. Sysdig said it could not determine which underlying AI model powered the agent, and that the payloads contained natural language reasoning and self-narration typical of large language model output rather than a fixed, pre-scripted toolkit.

- Advertisement -
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

- Advertisment -