JADEPUFFER
actor · actor:jadepuffer single-source
JADEPUFFER, agentic threat actor documented by Sysdig (2026-07-01) as the first observed end-to-end ransomware/extortion operation driven autonomously by an LLM; entered via Langflow CVE-2025-3248 and abused default MinIO/Nacos credentials on internet-exposed infrastructure. Tracked by Microsoft under the designation Storm-3168 (2026-09-25 Azure resource-destruction reporting).
Aliases: Storm-3168
Coverage
3
2 about it · 1 mention · first 2026-07-04 → last 2026-09-28
Latest activity
2026-09-28
Microsoft ties JADEPUFFER's cloud operations to a service principal that enumerated an Azure tenant for 15+…
Peak priority
high
1 high · 1 notable
Targets
public-sector
sectors: public-sector, technology, education
Sources cited
9
8 hosts
2026-07-043 appearances2026-09-28
Action items (5)
Do-now tasks recorded on the entries about JADEPUFFER, newest first. Check the date before acting on an older one.
- Rotate every Azure service-principal client secret, tenant ID or connection string that has ever appeared in a public GitHub issue, PR, commit or gist, including ones since edited or deleted.2026-09-28Microsoft ties JADEPUFFER's cloud operations to a…
- Patch Langflow to ≥ 1.3.0 and remove the code-validation/execution endpoint from internet exposure; the initial-access CVE has been on CISA KEV since May 2025.2026-07-04CVE-2025-3248
- Rotate MinIO and Nacos default credentials (minioadmin:minioadmin; Nacos default token.secret.key) and stop Nacos authenticating to its backing database as root.2026-07-04CVE-2025-3248
- Egress-filter AI-orchestration and application hosts so a compromised server cannot reach arbitrary external databases or staging infrastructure, and move LLM-provider/cloud credentials into a secrets manager off web-reachable hosts.2026-07-04CVE-2025-3248
- For any Langflow or self-hosted AI-pipeline estate, confirm model checkpoints and training datasets are backed up to storage isolated from the compute host, ENCFORGE encrypts ~180 ML-artifact file types and any training data sitting on the same host, so a co-located backup is inside the blast radius and recovery would otherwise mean re-training from scratch.2026-07-04CVE-2025-3248
Defender insights
What each entry about JADEPUFFER tells a defender to do, newest first.
Triage · detection
Latest update
Story timeline
Every entry that names JADEPUFFER, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-09-28Storm-3168 (JADEPUFFER): a sub-eight-minute, automated Azure resource-destruction campaign via a service-principal secret that stayed valid in a GitHub issue's edit history after the visible text was redacted
- 2026-08-28A near-autonomous, multi-agent AI framework compromised Taiwanese government infrastructure over four days, cracking 85 accounts, exfiltrating 2,564+ personnel records, and bypassing its own safety guardrails by reframing itself as 'authorized penetration testing'
- 2026-07-04JADEPUFFER, Sysdig documents an autonomous, LLM-driven ransomware operation entering via Langflow CVE-2025-3248
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (9 across 7 tactics)
9 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts · Valid Accounts: Cloud Accounts · Exploit Public-Facing Application
- PersistenceValid Accounts · Valid Accounts: Cloud Accounts
- Privilege EscalationValid Accounts · Valid Accounts: Cloud Accounts · Escape to Host
- StealthValid Accounts · Valid Accounts: Cloud Accounts
- Credential AccessUnsecured Credentials
- DiscoveryCloud Service Discovery
- ImpactData Destruction · Data Encrypted for Impact · Inhibit System Recovery
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-09-28/storm-3168-jadepuffer-azure-destructive-service-principal · ATT&CK page ↗
T1190Exploit Public-Facing Application×2
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-09-28/storm-3168-jadepuffer-azure-destructive-service-principal · 2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-09-28/storm-3168-jadepuffer-azure-destructive-service-principal · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-09-28/storm-3168-jadepuffer-azure-destructive-service-principal · ATT&CK page ↗
T1611Escape to Host×1
Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.
Evidence: 2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-09-28/storm-3168-jadepuffer-azure-destructive-service-principal · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce · ATT&CK page ↗
Discovery TA0007
T1526Cloud Service Discovery×1
An adversary may attempt to enumerate the cloud services running on a system after gaining access. These methods can differ from platform-as-a-service (PaaS), to infrastructure-as-a-service (IaaS), or software-as-a-service (SaaS). Many services exist throughout the various cloud providers and can include Continuous Integration and Continuous Delivery (CI/CD), Lambda Functions, Entra ID, etc. They may also include security services, such as AWS GuardDuty and Microsoft Defender for Cloud, and logging services, such as AWS CloudTrail and Google Cloud Audit Logs.
Evidence: 2026-09-28/storm-3168-jadepuffer-azure-destructive-service-principal · ATT&CK page ↗
Impact TA0040
T1485Data Destruction×2
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.
Evidence: 2026-09-28/storm-3168-jadepuffer-azure-destructive-service-principal · 2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce · ATT&CK page ↗
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce · ATT&CK page ↗
T1490Inhibit System Recovery×1
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Evidence: 2026-09-28/storm-3168-jadepuffer-azure-destructive-service-principal · ATT&CK page ↗
Entries about JADEPUFFER (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Hermes AI agent×1
- Keycloak×1
- knaithe / KnYuan×1
- Langflow×1
- Langflow /api/v1/validate/code missing-auth RCE, initial access for the JADEPUFFER agentic ransomware operation×1
- Microsoft Azure×1
- OAuth 2.0 / OpenID Connect discovery endpoints×1
- Taiwan near-autonomous AI government intrusion (July 2026)×1
Where this entity is cited
Source distribution
- sysdig.com2 (22%)
- dreamgroup.com1 (11%)
- infosecurity-magazine.com1 (11%)
- microsoft.com1 (11%)
- moda.gov.tw1 (11%)
- tenable.com1 (11%)
- thehackernews.com1 (11%)
- unit42.paloaltonetworks.com1 (11%)
All cited sources (9)
- dreamgroup.comDream Securityhttps://dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia
- infosecurity-magazine.comInfosecurity Magazinehttps://www.infosecurity-magazine.com/news/jadepuffer-ai-model-ransomware/
- microsoft.comMicrosoft Security Blog / Microsoft Security Researchhttps://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/
- moda.gov.twTaiwan Administration for Cyber Security / Ministry of Digital Affairshttps://moda.gov.tw/ACS/press/news/press/20394
- sysdig.comSysdig Threat Research Teamhttps://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion
- sysdig.comSysdig Threat Research Teamhttps://www.sysdig.com/blog/jadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models
- tenable.comTenable Research Special Operations (RSO) teamhttps://www.tenable.com/blog/the-agentic-ai-threat-cluster-seven-incidents-three-actors-and-what-they-mean
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html
- unit42.paloaltonetworks.comPalo Alto Networks Unit 42 (background, the knaithe/KnYuan case of the same cluster, already covered)https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/