Sysdig 报告首个 LLM 智能体驱动的勒索软件 JADEPUFFER

Rohan Paul · @rohanpaul_ai · X·2026-07-04 02:37·60天前
AI 导读

Sysdig 将 JADEPUFFER 定义为首个完全由大语言模型(LLM)智能体驱动的勒索软件。攻击目标为开源 AI 构建工具 Langflow,利用其缺失认证漏洞在暴露服务器上执行 Python 代码。智能体随后搜索 API 密钥、云凭证、加密钱包及数据库登录,横向移动至生产数据库服务器。它生成了 600 多个针对性 payload 并根据条件调整行为。与常规勒索软件不同,该智能体未保留可用的恢复密钥,直接损坏数据且无法恢复。

Rohan Paul@rohanpaul_ai
61AI 编辑部评分,满分 100

Sysdig 报告首个 LLM 智能体驱动的勒索软件 JADEPUFFER

2026-07-04 02:37· 60天前
AI 导读

Sysdig 将 JADEPUFFER 定义为首个完全由大语言模型(LLM)智能体驱动的勒索软件。攻击目标为开源 AI 构建工具 Langflow,利用其缺失认证漏洞在暴露服务器上执行 Python 代码。智能体随后搜索 API 密钥、云凭证、加密钱包及数据库登录,横向移动至生产数据库服务器。它生成了 600 多个针对性 payload 并根据条件调整行为。与常规勒索软件不同,该智能体未保留可用的恢复密钥,直接损坏数据且无法恢复。

Ransomware has crossed from scripted automation to autonomous AI decision-making.

An LLM agent allegedly chained hacking steps into a full ransomware operation.

Sysdig calls JADEPUFFER the first documented ransomware operation driven fully by an LLM.

The target was Langflow, an open-source tool used to build AI applications and agents.

A missing-authentication bug let the agent run Python code on an exposed server.

From there, it searched for API keys, cloud credentials, crypto wallets, and database logins.

The agent then moved through reachable internal services and found a production database server.

Old security failures did most of the damage, including default keys and weak exposure.

The new part was not genius, but the steady chaining of ordinary attack steps.

Human ransomware usually needs planning, retries, and judgment when a step breaks.

This system generated more than 600 purposeful payloads and adjusted as conditions changed.

This was not “normal ransomware” in the usual criminal sense.

Normal ransomware encrypts your data but keeps a working decryption key, because the attacker wants payment and needs a way to restore files after payment.

In this case, the AI agent apparently damaged the data without preserving a usable recovery key

---

yahoo .com/news/science/articles/ai-just-carried-cyber-attack-130824384.html