An AI agent just executed what researchers believe is the first real-world ransomware attack powered by an autonomous large language model. A human still chose the victim, built the infrastructure, and handed over the stolen credentials. The machine did the dirty work, but the architect was flesh and blood.
Cybersecurity firm Sysdig published its findings on July 1, 2026, attributing the attack to a threat actor dubbed JadePuffer. The incident, which took place in late June 2026, exploited a critical vulnerability in Langflow, tracked as CVE-2025-3248, to compromise an internet-exposed instance of the application connected to Alibaba Nacos and MySQL databases.
What the AI actually did
Once inside, the LLM agent ran the full playbook. Reconnaissance, credential harvesting, lateral movement, privilege escalation, and finally, database encryption on a MySQL/Nacos server. The attack destroyed 1,342 configuration items in the process.
The LLM was specifically programmed to scan for cryptocurrency wallets and seed phrases. It also hunted for API keys from major cloud providers including AWS, Azure, GCP, Alibaba/Aliyun, and Tencent.










