Skip to content

JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion

Gbhackers Mayura Kathir July 2, 2026

The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a […]

Extracted Entities

Attack Types (1)

Companies (1)

CVEs (1)

Platforms (2)

Ransomware Groups (1)