← Founder Notes
Archive

The first confirmed end-to-end agentic ransomware ran itself. sysdig documented an ai agent that…

Yethikrishna ROriginal on Threads

the first confirmed end-to-end agentic ransomware ran itself. sysdig documented an ai agent that exploited a vulnerable server, moved laterally, encrypted over 1,300 database records and recovered from a failed step in 31 seconds without a human.

the bottleneck is no longer building the attack.

Context

Sysdig's Threat Research report, published about 1 July 2026, says it captured what it assesses to be the first documented case of agentic ransomware, an extortion operation driven end to end by a large language model. The operator, tracked as JADEPUFFER, entered through an internet-facing Langflow instance via CVE-2025-3248, then did data looting and lateral discovery and attacked a Nacos configuration server. Thirty-one seconds after a failed admin-login check, without human intervention, a corrective payload was issued, and the agent encrypted all 1,342 Nacos service configuration items with MySQL AES_ENCRYPT; the key was never stored, so the victim could not recover data even by paying.

How it compares

First is Sysdig's own assessment and not a universal first. The encrypted items were 1,342 configuration items, not database records in general. The 31 second step was a corrective payload at a backdoor-admin step before the ransomware phase, not a failed encryption. Confirmed rests on Sysdig's captured payloads, and the victim and independent confirmation were not read. The report is about 1 July 2026, not new on 20 September. The bottleneck is no longer building the attack is the author's take.

Watch next

  • Other vendors' independent write-ups and any attribution or victim disclosure.

Sources

  1. JADEPUFFER: agentic ransomware for automated database extortion (Sysdig)sysdig.com

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 20 September 2026 at 07:56 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-first-confirmed-end-to-end-agentic-ransomware-DdfgoU1iIfm" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The first confirmed end-to-end agentic ransomware ran itself. sysdig documented an ai agent that…"></iframe>

More notes