<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/jadepuffer-the-first-successful-llm-driven-ransomware-attack-ttpa7zod8" -->

---
title: JadePuffer: The First Successful LLM-Driven Ransomware...
description: Sysdig researchers have documented JadePuffer, the first confirmed end-to-end ransomware campaign autonomously executed by an LLM agent without human operator...
canonical: https://daily.dev/posts/jadepuffer-the-first-successful-llm-driven-ransomware-attack-ttpa7zod8
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: JadePuffer: The First Successful LLM-Driven Ransomware Attack | daily.dev
og:description: Sysdig researchers have documented JadePuffer, the first confirmed end-to-end ransomware campaign autonomously executed by an LLM agent without human operator...
og:url: https://daily.dev/posts/jadepuffer-the-first-successful-llm-driven-ransomware-attack-ttpa7zod8
og:image: https://api.daily.dev/og/posts/Ttpa7ZOD8.png
og:image:alt: JadePuffer: The First Successful LLM-Driven Ransomware Attack
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# JadePuffer: The First Successful LLM-Driven Ransomware Attack

**[Dark Reading](https://daily.dev/sources/dr)** · 5 min read · 1 upvotes · 0 comments

## Summary

Sysdig researchers have documented JadePuffer, the first confirmed end-to-end ransomware campaign autonomously executed by an LLM agent without human operator involvement. The attack exploited CVE-2025-3248, an unauthenticated RCE vulnerability in Langflow, to pivot to a production MySQL database server, exfiltrate data, delete the database, and leave an extortion note. While the individual techniques were not novel, the AI agent chained reconnaissance, credential theft, lateral movement, and destruction in real time — recovering from a failed login in 31 seconds. Sysdig warns this marks a paradigm shift in extortion tradecraft, with recommendations including patching Langflow, isolating AI-orchestration credentials, and moving to continuous environment monitoring rather than periodic assessments.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack>

## Similar posts on daily.dev

- [JadePuffer Signals a New Era of AI-Driven Ransomware](https://daily.dev/posts/jadepuffer-signals-a-new-era-of-ai-driven-ransomware-rvacyt3ln) · Security Boulevard · 0 upvotes · 0 comments
- [JadePuffer ransomware used AI agent to automate entire attack](https://daily.dev/posts/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack-egb37hxoo) · BleepingComputer · 12 upvotes · 4 comments
- [JadePuffer Demonstrates How AI Agents Can Automate Ransomware Attack](https://daily.dev/posts/jadepuffer-demonstrates-how-ai-agents-can-automate-ransomware-attack-yxxnlhy7h) · Security Boulevard · 0 upvotes · 0 comments
- [JADEPUFFER: Agentic ransomware for automated database extortion](https://daily.dev/posts/jadepuffer-agentic-ransomware-for-automated-database-extortion-mbyibpyqo) · Sysdig Blog · 0 upvotes · 0 comments
- [AI agent runs first end-to-end ransomware attack](https://daily.dev/posts/ai-agent-runs-first-end-to-end-ransomware-attack-ulfxi7gog) · The Next Web · 1 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#ransomware](https://daily.dev/tags/ransomware), [#agentic-ai](https://daily.dev/tags/agentic-ai)

[View this post on daily.dev](https://daily.dev/posts/jadepuffer-the-first-successful-llm-driven-ransomware-attack-ttpa7zod8)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"JadePuffer: The First Successful LLM-Driven Ransomware Attack","url":"https://daily.dev/posts/jadepuffer-the-first-successful-llm-driven-ransomware-attack-ttpa7zod8","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/jadepuffer-the-first-successful-llm-driven-ransomware-attack-ttpa7zod8"},"datePublished":"2026-07-06T17:42:30.924Z","dateModified":"2026-07-06T17:42:55.209Z","description":"Sysdig researchers have documented JadePuffer, the first confirmed end-to-end ransomware campaign autonomously executed by an LLM agent without human operator...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8a897ca9cdc777e43e2107427fbffd42?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8a897ca9cdc777e43e2107427fbffd42?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/jadepuffer-the-first-successful-llm-driven-ransomware-attack-ttpa7zod8","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,ransomware,agentic-ai","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"JadePuffer: The First Successful LLM-Driven Ransomware Attack"}]}
```

