{"id":95747,"date":"2026-07-05T18:42:08","date_gmt":"2026-07-05T18:42:08","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/95747\/"},"modified":"2026-07-05T18:42:08","modified_gmt":"2026-07-05T18:42:08","slug":"ai-agent-pulls-off-a-ransomware-attack-without-human-help","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/95747\/","title":{"rendered":"AI Agent Pulls Off a Ransomware Attack Without Human Help"},"content":{"rendered":"<p class=\"text-muted\">\n                                            <a href=\"https:\/\/www.bankinfosecurity.com\/agentic-ai-c-940\" id=\"asset_topic_1_1\" rel=\"nofollow noopener\" target=\"_blank\">Agentic AI<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/fraud-management-cybercrime-c-409\" id=\"asset_topic_1_2\" rel=\"nofollow noopener\" target=\"_blank\">Fraud Management &amp; Cybercrime<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/ransomware-c-399\" id=\"asset_topic_1_3\" rel=\"nofollow noopener\" target=\"_blank\">Ransomware<\/a>\n                                                    <\/p>\n<p>                    Researchers Say the Attack Combined AI Decision-Making With Known Software Flaws<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/pooja-tikekar-i-5947\" rel=\"nofollow noopener\" target=\"_blank\">Pooja Tikekar<\/a> (<a href=\"https:\/\/www.twitter.com\/@PoojaTikekar\" rel=\"nofollow noopener\" target=\"_blank\">@PoojaTikekar<\/a>)                                                    \u2022<br \/>\n                        July 5, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/ai-agent-pulls-off-ransomware-attack-without-human-help-a-32155#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/ai-agent-pulls-off-ransomware-attack-without-human-help-image_large-6-a-32155.jpg\" alt=\"AI Agent Pulls Off a Ransomware Attack Without Human Help\" class=\"img-responsive \"\/><br \/>\n                Image: Magnific            <\/p>\n<p>An autonomous artificial intelligence agent has carried out what researchers describe as the first agentic ransomware attack, exploiting vulnerabilities, stealing credentials and encrypting a production database without human intervention.<\/p>\n<p>See Also: <a href=\"https:\/\/www.bankinfosecurity.com\/know-thy-enemy-threats-to-cyber-resilience-a-31674?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">Know Thy Enemy: Threats to Cyber Resilience<\/a><\/p>\n<p>Cloud security firm Sysdig <a href=\"https:\/\/www.sysdig.com\/blog\/jadepuffer-agentic-ransomware-for-automated-database-extortion\" target=\"_blank\" rel=\"nofollow noopener\">attributed<\/a> it to a threat actor it tracks as Jadepuffer. Researchers said the incident shows that large language models can autonomously execute a full ransomware life cycle, including reconnaissance, credential theft, lateral movement, privilege escalation and data encryption.<\/p>\n<p>The intrusion began with the exploitation of <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-3248\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2025-3248<\/a>, a critical authentication bypass vulnerability in Langflow&#8217;s code validation endpoint. Langflow is an open-source framework used to build AI applications and agent workflows. The flaw enables unauthenticated remote code execution on exposed servers and was added to CISA&#8217;s Known Exploited Vulnerabilities <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=All&amp;url=\" target=\"_blank\" rel=\"nofollow noopener\">catalog<\/a> in May.<\/p>\n<p>After gaining access, Jadepuffer searched the compromised environment for cloud credentials, API keys, cryptocurrency wallets, configuration files and database secrets. It dumped Langflow&#8217;s PostgreSQL database to harvest stored credentials, scanned internal networks and accessed an exposed MinIO object storage service using default credentials. Researchers said the agent also established persistence by deploying a cron job that beaconed to attacker-controlled infrastructure every 30 minutes.<\/p>\n<p>Using the harvested credentials, the AI agent moved to a separate, internet-exposed production server running MySQL and Alibaba&#8217;s Nacos configuration platform. It exploited <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-29441\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2021-29441<\/a>, abused Nacos&#8217; default JWT signing key and injected a backdoor administrator account into the platform&#8217;s database before launching the extortion phase.<\/p>\n<p>The ransomware encrypted 1,342 Nacos configuration records using MySQL&#8217;s AES_ENCRYPT() encryption functions, deleted the original tables and replaced them with a ransom note demanding payment in Bitcoin.<\/p>\n<p>Sysdig said the AI agent adapted when an attempt to create an administrator account failed, diagnosing the error and generating a working alternative within 31 seconds. Researchers also identified hundreds of payloads containing natural-language reasoning and self-generated annotations explaining the agent&#8217;s decisions.<\/p>\n<p>The attack did not rely on zero-day vulnerabilities or novel techniques. Instead, it combined known vulnerabilities, exposed services, default credentials and publicly documented weaknesses into an automated intrusion chain.<\/p>\n<p>Sysdig said it found no evidence that the attackers retained a decryption key or backup of the encrypted data, suggesting victims would be unable to recover their information even if they paid the ransom.<\/p>\n<p>            <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Agentic AI , Fraud Management &amp; Cybercrime , Ransomware Researchers Say the Attack Combined AI Decision-Making With Known&hellip;\n","protected":false},"author":2,"featured_media":95748,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,49456,24,25,8174,8429,50035,4322,313,50038,3825,49413,50034,1807,8431,415,50036,50037,38003,3826,19417],"class_list":["post-95747","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-agentic-ransomware","tag-ai","tag-artificial-intelligence","tag-autonomous-ai","tag-credential-theft","tag-cve-2025-3248","tag-cyberattack","tag-cybersecurity","tag-database-encryption","tag-extortion","tag-jadepuffer","tag-langflow","tag-large-language-model","tag-lateral-movement","tag-llm","tag-mysql","tag-nacos","tag-privilege-escalation","tag-ransomware","tag-sysdig"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/95747","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=95747"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/95747\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/95748"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=95747"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=95747"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=95747"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}