Autonomous AI Agent Used in Ransomware Attack
Still_Piglet9217 · reddit · 2026-07-13
Sharing a Sysdig report, a Reddit post reveals that an LLM agent named JadePuffer was built to autonomously breach networks, steal credentials, move laterally, and encrypt databases for ransom.
Key points include:
- The initial attack vector was an unauthenticated remote code execution vulnerability in Langflow.
- The agent could automatically handle login failures, rewrite its own code, and continue the attack.
- It shifted from a failed login to a working exploit chain in about 31 seconds.
- It also established scheduled callbacks, created rogue admin accounts, and encrypted numerous service configurations.
The author stresses that this proves "plan-act-observe" agent architectures can be used to build malicious systems from scratch, not just as hijacked assistants. Any internet-exposed orchestration systems should be patched immediately.
More from coding & agent
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- Treating agents like 50 First Dates: a 3-layer context system so every conversation doesn't start from zero — evielync · 2026-09-11
- SmolVM open-sources persistent computer infrastructure for agents that outlive chat sessions — aniketmaurya · 2026-09-11
- ARRM targets silent economic regressions in AI agents that functional tests miss — Beautiful_Belt_601 · 2026-09-11
- Dev builds browser 3D pizza delivery game with Claude: physics, GPS pathfinding, traffic AI — vinishkapoor · 2026-09-11
- Build X Carousel Posts from One Wide Image: A Splitter Tool Plus YouMind Skill Workflow — sujingshen · 2026-09-11