Skip to main content
  1. Home
  2. Emerging Tech
  3. News

AI agent reportedly carried out an entire ransomware attack on its own

AI didn't just write malware. It apparently clocked in for work.

Add as a preferred source on Google
Cybersecurity
Cybersecurity Unsplash

Cybersecurity researchers say they have documented what could be the first ransomware attack carried out almost entirely by an autonomous AI agent, marking a significant shift in how cyberattacks could be conducted in the future. According to cloud security firm Sysdig, they have uncovered a ransomware operation dubbed JadePuffer that appears to have relied on a large language model (LLM) agent to perform nearly every stage of the attack without continuous human intervention.

If confirmed, the incident suggests AI is moving beyond writing malicious code and into actively planning, adapting, and executing cyberattacks in real time.

JadePuffer adapted to obstacles much like a human hacker

According to Sysdig’s findings, JadePuffer began by exploiting CVE-2025-3248, a remote code execution vulnerability in Langflow, an open-source framework used to build LLM-powered applications. The flaw, patched in April 2025, was later added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) list of vulnerabilities known to be exploited in the wild.

Once inside the system, the AI agent reportedly carried out a full attack chain that security researchers typically associate with experienced human operators. It collected host information, searched for credentials and sensitive files, extracted cloud secrets, and mapped storage resources before moving laterally through the victim’s infrastructure.

What stood out wasn’t simply the automation – it was the adaptability.

According to the Sysdig report, the researchers observed the AI agent responding dynamically when certain commands failed. In one instance, the malware encountered an unexpected XML response while querying a MinIO object store. Instead of failing, the agent modified its parsing logic and retried using a different approach. Researchers also documented a failed login attempt that was automatically corrected within 31 seconds, without requiring human input.

Recommended Videos

The AI later established persistence by creating scheduled cron jobs before pivoting to a production server running Alibaba Nacos, where it exploited CVE-2021-29441 to create rogue administrator accounts. It eventually encrypted 1,342 Nacos configuration records, deleted the original data, and replaced it with a ransom note demanding payment in Bitcoin.

Interestingly, researchers found several signs suggesting the operation was AI-generated. The malicious code contained unusually detailed natural-language comments explaining its own reasoning, while the ransom note referenced a Bitcoin wallet commonly used as an example in documentation rather than a genuine payment address. Sysdig also believes the malware likely used AES-128 in ECB mode, despite claiming AES-256 encryption.

The findings arrive as cybersecurity experts increasingly warn about the emergence of agentic AI, where AI systems can independently plan and execute complex tasks rather than simply responding to prompts. While JadePuffer still exploited known vulnerabilities rather than inventing new attack methods, the ability to autonomously perform reconnaissance, privilege escalation, persistence, and ransomware deployment represents a notable escalation in offensive AI capabilities.

Sysdig says the incident demonstrates that “agentic threat actors” have effectively arrived, potentially lowering the technical expertise required to launch sophisticated cyberattacks. At the same time, researchers note that AI-generated attacks may also leave distinct behavioural patterns and coding characteristics that defenders can use to build new detection techniques.

For organizations, the report serves as another reminder that patching internet-facing systems and securing cloud credentials remain essential – even as the attackers themselves begin to change.

Moinak Pal
Moinak Pal is has been working in the technology sector covering both consumer centric tech and automotive technology for the…
After a week with Gemini Notebook on my Galaxy Z Fold 8 Ultra, I can’t imagine using it on a slab phone
Computer, Electronics, Screen

Gemini Notebook has become one of the apps I use more than almost anything else. Whether I'm researching for a feature, studying for hours, or trying to make sense of a stack of PDFs, it's almost always open somewhere on my phone. Over the past years, I've used it on just about every kind of device imaginable, but one thing kept bothering me. It never really felt like a notebook.

Don't get me wrong — it worked perfectly well on a regular phone. All the features were there, and I never felt like I was missing anything. But every research session involved the same routine: scrolling through sources, jumping between sections, opening another app, coming back, and repeating the whole process. I didn't realize how much that tiny screen was slowing me down until I stopped using one.

Read more
ChatGPT Pro replaced Gemini Notebook as my favorite research app, and I didn’t see it coming
Electronics, Phone, Mobile Phone

I've been using Gemini Notebook ever since it launched, and for the longest time, it was my go-to app for just about everything. Whether I was researching a topic, organizing work, or studying something new, it became one of those apps I instinctively opened without thinking. When Google kept adding new features, I genuinely believed it had secured a permanent spot in my workflow.

Then, almost without realizing it, ChatGPT Pro took over. I've been using its Work mode for a while now, and somewhere along the way, it replaced Gemini Notebook. Of course, it wasn't an overnight switch. I kept bouncing between the two for weeks, but I gradually found myself reaching for ChatGPT every single time instead. At some point, I realized I hadn't opened Gemini Notebook in days. Now, I honestly don't use it at all.

Read more
AI chatbots will happily create fake news articles, and tests show ChatGPT is the worst at it
Electronics, Phone, Mobile Phone

The biggest AI chatbots are supposed to help people find information, not manufacture misinformation. But a new investigation suggests that separating those two jobs isn't as straightforward as many AI companies would like users to believe. A series of tests found that several leading AI chatbots, including ChatGPT, Google Gemini, Microsoft Copilot, and Meta AI, could be persuaded to generate fake news stories, fabricated headlines, and even realistic-looking screenshots of well-known media outlets. While every chatbot showed some weaknesses, ChatGPT reportedly performed the worst, producing the most convincing fake content with surprisingly little effort.

The findings come from an investigation by German newsroom CORRECTIV, which tested how the AI assistants responded when asked to create false reports involving sensitive topics such as election fraud, government coups, war, vaccines, climate change, and conspiracy theories.

Read more