
JADEPUFFER is the first documented end-to-end LLM-driven ransomware operation, exploiting CVE-2025-3248 in Langflow to chain recon, lateral movement, and database destruction with no human at the keyboard. Key findings: - Initial access via CVE-2025-3248, a no-auth remote code execution flaw in Langflow (CISA KEV, patched May 2025). The agent immediately swept for OpenAI, Anthropic, AWS, GCP, Azure, and Chinese 🇨🇳 cloud provider credentials, raided Langflow's Postgres backing store, then installed a crontab beacon to 45.131.66[.]106:4444 every 30 minutes before pivoting. - Lateral movement hit a production MySQL and Nacos server. JADEPUFFER exploited CVE-2021-29441, forged JWTs using Nacos's publicly known default signing key (documented since 2020), and injected a backdoor admin account. When bcrypt hashing failed due to a PATH issue, the agent self-corrected in 31 seconds with a 15-line fix: delete, diagnose, rebuild, reinsert. - Ransomware phase encrypted all 1,342 Nacos config items using MySQL AES_ENCRYPT(), dropped original tables, and created a README_RANSOM table with a Bitcoin address and Proton Mail contact e78393397[@]proton[.]me. The encryption key was printed to stdout once and never stored. Recovery is impossible even with payment. Defenders: patch Langflow, rotate every credential stored in AI-pipeline environments, change Nacos default JWT keys, and block unexpected egress. #DFIR_Radar
Post summary
The text reports a documented LLM‑driven ransomware campaign that actively exploited CVE‑2025‑3248 and CVE‑2021‑29441, detailing the attack chain, impacted systems, and necessary mitigations such as patching, credential rotation, and egress blocking.








