Sysdig
aidefend-sf0009
JADEPUFFER Agentic Ransomware via Langflow RCE
- Autonomous Agents
- AI Infrastructure
- Financial Fraud & Abuse
- System Compromise & RCE
Sysdig reported JADEPUFFER exploiting Langflow CVE-2025-3248, executing Base64-encoded Python payloads, harvesting secrets from the Langflow host and backing services, discovering reachable MinIO, Nacos, and MySQL infrastructure, abusing Nacos/MySQL access, encrypting Nacos configuration rows, writing ransom artifacts, and dropping database schemas.
Mapped threat techniques
AML.T0049Exploit Public-Facing ApplicationAML.T0050Command and Scripting InterpreterAML.T0075Cloud Service DiscoveryAML.T0112.000Machine Compromise: Local AI AgentAML.T0055Unsecured CredentialsAML.T0021Establish AccountsAML.T0105Escape to HostAML.T0059Erode Dataset IntegrityAML.T0029Denial of AI Service