Date: 07/22/2026
Severity: High
Summary
JADEPUFFER is the first documented agentic ransomware campaign where a large language model (LLM) autonomously executed the entire attack chain from initial compromise and credential theft to lateral movement and database extortion. It exploited an unpatched Langflow instance (CVE-2025-3248), adapted its actions in real time, and even generated self-narrating payloads during the intrusion. The campaign highlights how AI-driven automation can significantly lower the barrier to launching sophisticated ransomware attacks and accelerate the speed of extortion operations.
Indicators of Compromise (IOC) List
Domain/Urls | http://45.131.66.106:4444/beacon |
IP Address | 45.131.66.106 64.20.53.230 |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "http://45.131.66.106:4444/beacon" or url like "http://45.131.66.106:4444/beacon" or siteurl like "http://45.131.66.106:4444/beacon" |
Detection Query 2 : | dstipaddress IN ("45.131.66.106","64.20.53.230") or srcipaddress IN ("45.131.66.106","64.20.53.230") |
Reference:
https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion