{"id":96528,"date":"2026-07-06T15:37:07","date_gmt":"2026-07-06T15:37:07","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/96528\/"},"modified":"2026-07-06T15:37:07","modified_gmt":"2026-07-06T15:37:07","slug":"sysdig-clocks-first-documented-case-of-agentic-ransomware","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/96528\/","title":{"rendered":"Sysdig clocks first documented case of agentic ransomware"},"content":{"rendered":"<p>Artificial intelligence is claiming many firsts as it permeates every layer of technology, including the tools cybercriminals use to break into networks, steal sensitive data, hop into connected systems and deploy malware.\u00a0<\/p>\n<p>This includes, for the first time, according to Sysdig researchers, <a href=\"https:\/\/www.sysdig.com\/blog\/jadepuffer-agentic-ransomware-for-automated-database-extortion\" rel=\"nofollow noopener\" target=\"_blank\">a case of agentic ransomware<\/a> managing an extortion operation spanning reconnaissance, credential theft, lateral movement, persistence, encryption, destruction and the delivery of the ransom note itself.<\/p>\n<p>The <a href=\"https:\/\/cyberscoop.com\/tag\/artificial-intelligence-ai\/\" rel=\"nofollow noopener\" target=\"_blank\">AI<\/a> agent didn\u2019t accomplish every step in the late June 2026 attack, but it allowed the threat actor, which Sysdig tracks as JadePuffer, to significantly reduce complexity, speed up the tempo and gain operational advantages.\u00a0<\/p>\n<p>\u201cWe have seen attackers script attacks for years, and we have seen AI speed up individual steps of attack chains,\u201d Michael Clark, senior director of threat research at Sysdig, told CyberScoop. However, this recent attack was \u201cdriven end-to-end by the model\u2019s own decision-making, rather than a human at the keyboard,\u201d he added.<\/p>\n<p>The AI-aided attack achieved initial access by exploiting a Langflow vulnerability \u2014 <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-3248\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2025-3248<\/a> \u2014 before moving on to its intended target: a production server running MySQL and Alibaba Nacos.\u00a0<\/p>\n<p>Sysdig observed multiple factors that bolstered what it described as the first documented use of agentic <a href=\"https:\/\/cyberscoop.com\/tag\/ransomware\/\" rel=\"nofollow noopener\" target=\"_blank\">ransomware<\/a>.<\/p>\n<p>The payloads involved in the attack narrated their objectives in plain language and identified high-value databases, details that large-language models annotate by default, according to Clark. The AI agent also quickly diagnosed problems and worked around obstacles \u2014 in one case redeploying a corrected payload 31 seconds after it originally encountered an error.<\/p>\n<p>Before it was all over, the AI agent ran more than 600 distinct, purposeful payloads in rapid succession.<\/p>\n<p>\u201cThe model closed loops that used to require a skilled human,\u201d Clark said. \u201cThe 31-second failure-to-fix cycle on the Nacos backdoor is the clearest example of where agentic AI gave the attacker an advantage. The agent read the error, switched its approach from subprocess calls to direct library imports, and redeployed at a speed no human matches.\u201d<\/p>\n<p>Sysdig researchers found evidence that multiple models were used in the attack. The agent accessed keys for OpenAI, Anthropic, DeepSeek and Gemini as it gathered information on the victim\u2019s systems. The cybersecurity vendor did not name the victim.<\/p>\n<p>The <a href=\"https:\/\/cyberscoop.com\/tag\/agentic-ai\" rel=\"nofollow noopener\" target=\"_blank\">AI agent<\/a> played a crucial role in the attack, but a person was still heavily involved, Clark said. \u201cA human still set up and pointed the operation and provisioned the infrastructure behind it, the command-and-control server, the staging server used for the stolen data and chose a victim,\u201d he added.<\/p>\n<p>The agent also connected to the victim\u2019s MySQL server with root credentials that were not lifted from the victim\u2019s environment, indicating a person gained access to the credential through a prior compromise.\u00a0<\/p>\n<p>The origins of JadePuffer, a financially motivated threat actor, are unknown and it doesn\u2019t overlap with any established ransomware group or nation state, researchers said.<\/p>\n<p>For Clark, there is a clear uncomfortable takeaway from this attack: \u201cThe skill floor for running a full ransomware operation just dropped to whatever it costs to run an agent,\u201d he said.\u00a0<\/p>\n<p>\u201cWe have not yet seen operations against other victims, and given how cheap this agentic ransomware operation is to run, I would expect this will not be the last.\u201d<\/p>\n<p>\t\t\t\t\t<img decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/MattKapko.jpg\" alt=\"Matt Kapko\"\/><\/p>\n<p>\n\t\t\tWritten by Matt Kapko<br \/>\n\t\t\tMatt Kapko is a reporter at CyberScoop. His beat includes cybercrime, ransomware, software defects and vulnerability (mis)management. The lifelong Californian started his journalism career in 2001 with previous stops at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt has a degree in journalism and history from Humboldt State University.\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"Artificial intelligence is claiming many firsts as it permeates every layer of technology, including the tools cybercriminals use&hellip;\n","protected":false},"author":2,"featured_media":96529,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,405,25,111,7537,154,49413,50034,3826,10718],"class_list":["post-96528","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-ai-agents","tag-artificial-intelligence","tag-artificial-intelligence-ai","tag-artificial-intelligence-agents","tag-cybercrime","tag-jadepuffer","tag-langflow","tag-ransomware","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/96528","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=96528"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/96528\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/96529"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=96528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=96528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=96528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}