JadePuffer: the first case of a full-fledged autonomous cyber attack using agent AI

Sysdig researchers have officially confirmed the first known case where an agent based on a large language model (LLM) was able to independently execute a complete cycle of a cyberattack. The malicious ransomware, called JadePuffer, worked autonomously, eliminating the need for human involvement in the management process.

During the attack, the AI ​​​​agent performed system reconnaissance, successfully stole credentials, secured a foothold in a compromised environment, elevated its privileges, and eventually encrypted the victim’s files.

Attack vector and technical details

The JadePuffer penetration began with the exploitation of the critical vulnerability CVE-2025-3248 in the Langflow platform, which is widely used by developers to build AI-based applications.

Results of automated hacking

  • System information collection and credential search are automated.
  • Unauthorized access to linked servers.
  • Successful attack on Alibaba Nacos server.
  • Encryption of 1342 configuration records.

Features of agent AI work

The main difference between JadePuffer and traditional malware is a high level of autonomy and adaptability. If the execution of a certain command led to an error, the agent did not stop work, but independently analyzed the situation, adjusted its actions and continued the attack. One of the clear examples is bypassing the authentication system in just 31 seconds.

Sysdig experts also noted unique artifacts in the generated code. The agent left comments in natural language that explained in detail the logic of the actions taken.

Code errors as a result of using LLM

Despite the technical complexity of the attack, the researchers emphasized the errors inherent in the work of current models. For example, the attacker used a test wallet, which is often found in training documentation, and instead of the claimed AES-256, the weaker encryption algorithm AES-128-ECB was actually used.

The future of cyber security

Experts warn that the use of such agents can significantly lower the entry threshold for cybercriminals, allowing for the automation of complex attack chains. However, there are still predictable traces (patterns) in the operation of current LLMs that allow modern monitoring systems to detect such threats. The expert community calls for more attention to be paid to the protection of environments using LLM development tools.


Don't miss interesting news

Subscribe to our channels and read announcements of high-tech news, tes

Leave a Reply

Your email address will not be published. Required fields are marked *





Articles & testsArticles

Oppo A6 Pro smartphone review: ambitious Oppo A6 Pro (CPH2799)

Creating new mid-range smartphones is no easy task. Manufacturers have to balance performance, camera capabilities, displays, and the overall cost impact of each component. How the new Oppo A6 Pro balances these factors is discussed in our review.


Guide for choosing Garmin smartwatches for sports, military and everyday life Garmin Instinct 3

Garmin has long gone beyond simple GPS navigation. Today, they are the ultimate computing centers on the wrist, competing with both classic “smart” wearable electronics and specialized professional devices. How to choose a Garmin smartwatch – we’ll tell you further


NewsNews
| 21.37
Crussis e-Full 12.11 Pro X: A 150 Nm E-MTB Beast Priced at €12K

Discover the new high-performance Crussis e-Full 12.11 Pro X electric mountain bike, featuring a powerful DJI Avinox motor and a carbon frame. We explore its technical specs, hardware, and whether it justifies its premium price.

| 21.02
One UI 9.5: first signs of development on Galaxy S27 Ultra

Data on an early build of the One UI 9.5 firmware for the flagship Samsung Galaxy S27 Ultra has leaked. We break down what the found S958U build indices signify.