---
title: "The attacker went agentic before you did"
date: 2026-07-14
series: 16
summary: "The first fully agentic ransomware just ran. It used the same primitives you build defensive agents on."
voice: judgment
tags: [agentic-ransomware, autonomous-attack-chain, agent-tempo, credential-blast-radius, self-narrating-payloads]
image: "/notes/jadepuffer-agentic-ransomware/image.png"
imageAlt: "attack chain (Langflow RCE, credential sweep, lateral move, encrypt) with the 31-second self-correction called out"
linkedin: urn:li:activity:7482652643744702465
sources:
  - title: "JadePuffer agentic ransomware writeup (CVE-2025-3248, 31s self-correction, 1,342 items encrypted, 600+ payloads) — Sysdig"
    url: https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
    date: 2026-07-01
  - title: "\"The first AI-run ransomware attack still needed a human\" framing — TechCrunch"
    url: https://techcrunch.com/2026/07/06/the-first-ai-run-ransomware-attack-still-needed-a-human/
    date: 2026-07-06
  - title: "First documented case of agentic ransomware — CyberScoop"
    url: https://cyberscoop.com/sysdig-judepuffer-ai-agentic-ransomware-attack/
    date: 2026-07-06
dateApprox: false
---

The first fully agentic ransomware just ran. It used the same primitives you build defensive agents on.

Sysdig documented JadePuffer this month: an LLM agent that ran the whole chain by itself. RCE into an exposed Langflow box, swept the host for provider keys and cloud creds, moved laterally into a Nacos/MySQL config server, installed a beacon, then encrypted 1,342 config items and wrote its own ransom note.

The entry point was not novel. CVE-2025-3248, patched April 2025. What was new is tempo. When a Nacos admin login failed, the agent diagnosed it and self-corrected in 31 seconds, switching from a subprocess call to a direct bcrypt import. No human triages that fast.

Sysdig caught it on 600+ distinct payloads, each one narrating its own targeting rationale in plain language. That self-narration is the fingerprint.

The trap: the agent's blast radius was exactly the creds and tools its host could reach. Same rule as your defensive agents. Leave provider keys sitting in your orchestration server env and you have scoped the attacker's reach for them.

Attackers went agentic before most defenders did. Your perimeter is now whatever your agent's tools can touch.
