First Fully Autonomous AI Agent Executes End-to-End Ransomware Attack Without Human Intervention
Cloud security firm Sysdig reported it detected the first documented end-to-end agentic ransomware operation, an actor it tracks as JADEPUFFER, gaining initial access to an internet-facing
Sysdig's JADEPUFFER case shows an autonomous agent can now run a full ransomware lifecycle end to end using only known CVEs, default credentials, and a public JWT signing key, collapsing coordination previously requiring a human intrusion crew into a single automated pass. The 31-second diagnose-and-correct sequence on the Nacos admin account indicates the agent adapting to failure mid-run rather than executing a fixed script, though the same behavior is also consistent with routine LLM code-generation habits rather than deliberate agentic judgment. Internet-facing Langflow and Nacos deployments running default configurations constitute a documented target set, since the agent's own payloads catalogued the exploitation path. Sourcing rests solely on Sysdig's technical writeup, with other outlets summarizing rather than independently verifying it, and defenders tuned to human operator tempo face detection gaps against intrusions that complete phases in seconds.
5 sources
- JADEPUFFER: Agentic ransomware for automated database extortion -
Sysdig - AI Agent Pulls Off a Ransomware Attack Without Human Help -
BankInfoSecurity - JadePuffer ransomware used AI agent to automate entire attack -
BleepingComputer - Smooth AI criminal drives 'first' end-to-end agentic ransomware attack -
The Register - Smooth AI criminal drives 'first' end-to-end agentic ransomware attack -
The Register