Sysdig TRT captured what it assesses as the first documented agentic ransomware — complete extortion operation driven end-to-end by an LLM. Operator dubbed JADEPUFFER; classified as agentic threat actor (ATA).
Entry: CVE-2025-3248 missing-authentication RCE in Langflow (patched April 2025, CISA KEV May 2025). Target: separate production MySQL + Alibaba Nacos server. Nacos auth bypass CVE-2021-29441 and default JWT signing key (public since 2020).
Novelty is autonomous chaining of known weaknesses, not zero-day exploits.
None of individual techniques were novel. JADEPUFFER demonstrates AI agents can chain neglected internet-facing infrastructure into complete extortion without deep per-step expertise.