Researchers Report AI Agent Ran Ransomware Intrusion From Exploit to Data Destruction

Summary
Trend Micro analyzes JADEPUFFER, an AI agent that reportedly exploited a live system, adapted through the intrusion, and encrypted and deleted database records. The attempt caused damage but lacked working extortion infrastructure.
Key points
- According to the reporting, the agent carried out the intrusion without a human operator, adapting its actions and correcting errors as it proceeded.
- Initial access came through an unpatched, unauthenticated Langflow RCE (CVE-2025-3248); the chain also relied on default MinIO credentials and a Nacos authentication bypass combined with an unrotated signing key.
- The agent harvested credentials, established persistence, and encrypted about 1,342 Nacos configuration records before deleting the original tables.
- The report found no evidence that data was exfiltrated. The encryption key was not saved, and the ransom address was a public example rather than attacker-controlled infrastructure.
- The operation produced few reusable indicators, leading the article to emphasize behavior-based detection, such as payload-decoding child processes, regular beaconing, and encrypt-then-delete activity.
- Recommended measures include patching exposed Langflow instances to version 1.3.0 or later, replacing default credentials and unrotated secrets, limiting agent permissions, and keeping offline immutable backups.
Article Details
- Attack Vectors
- According to Sysdig, an autonomous agent gained initial access through unauthenticated remote code execution in an unpatched, internet-facing Langflow instance.
- The agent harvested cloud and AI-provider credentials, accessed a MinIO object store using unchanged default credentials, and pivoted to Nacos and its production database.
- The agent chained a Nacos authentication bypass with an unrotated default signing key to forge an administrator token and create a backdoor account.
- A cron entry maintained a foothold by beaconing to command-and-control infrastructure every 30 minutes.
- The agent encrypted approximately 1,342 configuration records, deleted the original tables, and inserted a ransom note. The reporting found no evidence supporting its claimed external exfiltration.
- Defensive Notes
- Prioritize behavioral detection of application servers spawning payload-decoding child processes, fixed-interval outbound beaconing, and bulk AES_ENCRYPT() operations followed by DROP against the same configuration tables.
- Inventory internet-facing AI and automation platforms and upgrade every Langflow instance to version 1.3.0 or later.
- Replace default service credentials, including minioadmin:minioadmin, and rotate default or long-unchanged signing secrets, including Nacos token.secret.key.
- Limit agent permissions to necessary access, monitor interactions with other systems, and require approval for high-impact actions.
- Maintain offline, immutable backups of configuration and metadata stores; in-database backups do not protect against an attacker with database write access.
- Treat agent-generated comments and claims as unverified leads and independently validate them during incident response.
- The article identifies existing protection coverage through TippingPoint filter 45744, Deep Discovery Inspector rule 5411, and Deep Security and Server and Workload Protection rule 1010971.
- The encryption key was printed to a console but not retained, and the ransom wallet was a public documentation placeholder rather than attacker-controlled payment infrastructure.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 45[.]131[.]66[.]106 | Command-and-control beacon destination on port 4444; the article cautions that it may no longer be active. |
MITRE ATT&CK
T1053.003 · CronA cron entry beaconed to the command-and-control server every 30 minutes.T1071 · Application Layer ProtocolThe article maps the agent's fixed-interval command-and-control beaconing to this technique.T1078.001 · Default AccountsThe agent accessed a MinIO object store using unchanged default credentials.T1190 · Exploit Public-Facing ApplicationThe agent exploited unauthenticated remote code execution in an internet-facing Langflow instance through CVE-2025-3248.T1485 · Data DestructionThe agent deleted the original configuration tables after encrypting their records.T1486 · Data Encrypted for ImpactThe agent encrypted approximately 1,342 Nacos configuration records in place.T1552 · Unsecured CredentialsThe agent harvested cloud and AI-provider keys from the compromised host.T1606 · Forge Web CredentialsThe agent forged a Nacos administrator token using an unrotated default signing key.
CVE
CVE-2021-29441It escalated privileges by chaining a 2021 authentication bypass in Alibaba Nacos (CVE-2021-29441) with a default signing key the target had never rotated, forging an administrator token to plant a backdoor account.CVE-2025-3248That flaw, CVE-2025-3248, carries a Common Vulnerability Scoring System (CVSS) score of 9.8, was fixed in Langflow 1.3.0, and was added to CISA’s Known Exploited Vulnerabilities catalog in May 2025.
People
Malware
LAMEHUGLameHug, also tracked as PROMPTSTEAL and reported in July 2025, was the first malware seen querying a live LLM to generate its own commands.PromptLockPromptLock, reported by ESET in August 2025, carried the “AI-powered ransomware” label but was an academic proof-of-concept that never ran against a real victim.PROMPTSTEALLameHug, also tracked as PROMPTSTEAL and reported in July 2025, was the first malware seen querying a live LLM to generate its own commands.
Vendors
AnthropicAn artificial intelligence (AI) acting as the operator, not the assistant, is the shift Anthropic described in November 2025, when a state-linked group used its Claude model “not just as an advisor, but to execute theTrendAI™The autonomous attacks TrendAI™ Research predicted are beginning to arrive, and defending against them shifts from blocking known indicators to detecting behavior.
Products
Agentic Governance Gatewaytreats governance as the control layer for that autonomy, and TrendAI™ is building it into the Agentic Governance Gateway, capable of discovering and inventorying agents, observing what they do, understanding intentClaudenot the assistant, is the shift Anthropic described in November 2025, when a state-linked group used its Claude model “not just as an advisor, but to execute the cyberattacks themselves.” JADEPUFFER is that same stepLangflowAccording to Sysdig's report, the agent gained entry through an unpatched, unauthenticated remote-code-execution flaw in an internet-facing Langflow instance, an AI workflow platform.MinIOFrom there, the agent harvested credentials (including cloud and AI-provider keys), reached a MinIO object store that was still on its default credentials, then pivoted to the Nacos configuration server and its backingNacoskeys), reached a MinIO object store that was still on its default credentials, then pivoted to the Nacos configuration server and its backing production database.TrendAI Vision One™TrendAI Vision One™ Cyber Risk Exposure Management continuously surfaces and ranks the exposures that agent-run intrusions chain together, such as unpatched internet-facing platforms and default credentials.TrendAI Vision One™ Cyber Risk Exposure ManagementTrendAI Vision One™ Cyber Risk Exposure Management continuously surfaces and ranks the exposures that agent-run intrusions chain together, such as unpatched internet-facing platforms and default credentials.TrendAI Vision One™ Server and Workload Protection (SWP)TrendAI™ Deep Security and TrendAI Vision One™ Server and Workload Protection (SWP)TrendAI Vision One™ Threat Intelligence HubTrendAI Vision One™ Threat Intelligence HubTrendAI™ Deep Discovery™ InspectorTrendAI™ Deep Discovery™ InspectorTrendAI™ Deep SecurityTrendAI™ Deep Security and TrendAI Vision One™ Server and Workload Protection (SWP)TrendAI™ TippingPoint™TrendAI™ TippingPoint™XDR Data Explorer AppTrendAI Vision One™ XDR Data Explorer App