A threat actor tracked as JadePuffer has executed an agentic ransomware attack by exploiting a critical vulnerability in the open-source AI framework Langflow, marking a significant evolution in automated cyber extortion. According to a report from cloud security firm Sysdig, the attacker leveraged the CVE-2025-3248 flaw to gain initial access and then used the platform’s own large language model (LLM) capabilities to autonomously conduct reconnaissance, pivot across the network, and encrypt critical data. This incident demonstrates how artificial intelligence is lowering the barrier for sophisticated malicious operations.
What is the Langflow Vulnerability (CVE-2025-3248)?
Langflow is a Python-based, LLM-agnostic open-source framework designed for building LLM-driven applications and agent workflows. The vulnerability exploited in this attack, tracked as CVE-2025-3248, carries a critical CVSS score of 9.8 and involves a missing authentication flaw. Successful exploitation allows an unauthenticated attacker to execute arbitrary Python code on the host system where Langflow is running. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged the flaw as being actively exploited in early May 2025, shortly after its disclosure in April.
How the Agentic AI Ransomware Attack Unfolded
The attack by JadePuffer was a multi-stage operation that showcased the autonomous decision-making capabilities of the LLM. The process can be broken down into two primary phases.
Phase 1: Initial Access, Reconnaissance, and Credential Harvesting
After exploiting CVE-2025-3248 to gain code execution on an internet-exposed Langflow instance, the attacker used the LLM to perform automated reconnaissance. The AI system swept the host for sensitive data, including API keys, cloud credentials, cryptocurrency wallets, and database login information. It then dumped the Langflow instance’s Postgres database to harvest further secrets. The agent also scanned the reachable internal network address space and named services, probed for MinIO storage addresses for additional credential extraction, and deployed a cron job to maintain persistent access to the Langflow server. Throughout this initial phase, the LLM adapted its actions in real time to complete tasks, extracting credentials from various file types and logging into discovered endpoints.
Phase 2: Lateral Movement and Data Encryption
In the second phase of the operation, the LLM pivoted to a production server hosting a MySQL database and an Alibaba Naming and Configuration Service (Nacos) platform. The attacker connected to this server using a payload containing root credentials for the MySQL port. To compromise the Nacos service—which is notoriously vulnerable due to a well-known default JWT signing key and multiple security bypasses—the LLM exploited the auth-bypass flaw CVE-2021-29441 and forged a valid administrator JWT token. It then used its database access to inject a backdoor administrator account directly into Nacos’s backing database.
The AI agent then encrypted 1,342 Nacos service configuration items. Critically, it generated a random encryption key to lock the data but never persisted or transmitted that key, effectively making data recovery impossible. The attack concluded with the creation of an extortion table containing the ransom demand, a payment address, and a contact email. Sysdig noted that the payloads contained natural-language commentary on each action, indicative of LLM-generated code, and showed the AI correcting its own errors and adapting to failure states.
Why This Attack is a Turning Point for Cybersecurity
This incident represents a dangerous evolution in cyberattacks because the AI agent significantly lowered the barrier for a complex malicious operation. Rather than requiring a highly skilled human operator to chain together multiple exploits and maintain situational awareness, the attacker needed only a capable model and a known vulnerability to launch a successful, automated extortion campaign. The LLM was observed parsing free-text context from the target and taking actions that demonstrated genuine understanding, rather than simple pattern matching. This behavior recurred across multiple sessions weeks apart.
As Sysdig notes, defenders should expect the volume and breadth of such agentic campaigns to rise as the tooling matures. The AI combined known techniques against neglected infrastructure at near-zero cost to the attacker.
What Organizations Should Do to Mitigate This Threat
This attack underscores the critical importance of hardening exposed infrastructure. Organizations using frameworks like Langflow or configuration services like Nacos must apply the latest security patches immediately. For the immediate protection of your systems, consider the following steps:
- Patch and Update: Immediately apply patches for CVE-2025-3248 in any Langflow instance. Change default credentials for all configuration and database services (e.g., Nacos JWT signing keys).
- Harden Exposed Services: Treat any internet-exposed application server, unhardened configuration store, or database admin account as a primary attack surface. Implement network segmentation and strict access controls.
- Deploy a Multi-Layer Endpoint Protection Solution: Use a security platform that provides real-time threat detection, behavioral analysis, and anomaly detection to identify unusual lateral movement or data access patterns, such as a database being dumped by a web application.
- Monitor for Agentic Behavior: Traditional security tools may not flag multi-step, automated actions. Implement monitoring that correlates actions across systems and time to detect the subtle, logical chains of an agentic attack.
The era of the agentic attacker has arrived. By taking these proactive security measures, organizations can reduce their risk of becoming the next target of a fully automated, AI-driven ransomware campaign.