Skip to main content
Live
Main content

Sysdig's 'agentic ransomware' case still needed a human operator

JadePuffer's AI agent encrypted 1,300 records and wrote its own ransom note, but a human picked the target and staged the infrastructure.

Jaeden Schafer
Editor in Chief · · 5 min read
Sysdig's 'agentic ransomware' case still needed a human operator

Sysdig's much-discussed case of "agentic ransomware" — an extortion campaign the cloud-security firm dubbed JadePuffer — was not the fully autonomous attack early coverage suggested. In an interview with CyberScoop on Monday, Sysdig senior director of threat research Michael Clark clarified that a human operator still chose the victim, stood up the command-and-control server, ran the staging server for stolen data, and supplied database credentials harvested from an earlier compromise. What the AI handled was the technical execution: 1,300 configuration records encrypted, a fresh ransom note written by the model itself, and a Bitcoin address for payment.

The distinction matters because the campaign was initially described as running "without any human oversight," with "no human at the keyboard." The technical run was hands-off; the operation was not. That reframes JadePuffer from a fully autonomous attacker to a labor-saving tool bolted onto an otherwise conventional intrusion playbook.

The intrusion itself was straightforward. The agent entered through a known vulnerability in Langflow, a popular open-source tool for building LLM applications, then pivoted to a production MySQL server and exploited a second known flaw to gain admin access. From there it encrypted the 1,300 configuration records, swept the host for credentials, and left its ransom note. Sysdig has not disclosed the victim.

A human still set up and pointed the operation and provisioned the infrastructure behind it, the command-and-control server, the staging server used for the stolen data and chose a victim.
Michael Clark, Sysdig senior director of threat research

Key facts

  • 01Sysdig documented JadePuffer, an extortion campaign in which an AI agent broke in, moved laterally, and encrypted 1,300 configuration records on its own.
  • 02The agent fixed a failed login in 31 seconds, narrating its reasoning in natural-language code comments as it worked.
  • 03Sysdig's Michael Clark says a human still chose the victim, provisioned the command-and-control server, and supplied stolen database credentials.
  • 04The agent stole API keys tied to OpenAI, Anthropic, DeepSeek, and Gemini, but Sysdig could not identify which model actually drove the attack.
  • 05Microsoft researcher Geoff McDonald suspects an open-weight model with safety training stripped, not a frontier lab's model, ran the operation.

What stood out was the pace. The agent fixed a failed login in 31 seconds, narrating its own reasoning in natural-language code comments as it worked. That transparency — the model effectively logging its thinking as it moved — is the part experienced red-teamers found unusual. The techniques it used were ordinary; the speed and legibility were not.

One point that muddied early reporting has since been sorted out. Clark had told CyberScoop that "multiple models were used in the attack," citing API keys for OpenAI, Anthropic, DeepSeek, and Gemini that the agent had harvested. That phrasing left open the possibility that several frontier models were actively driving different stages of the intrusion. They were not.

Clark told TechCrunch by email that those keys were simply part of the loot, not evidence of what was running the show. He said Sysdig "was not able to identify the specific model driving the agent" and has no visibility into its system prompt or configuration.

That gap leaves the most interesting question open: which model has both the reasoning capability to carry out this kind of intrusion and lax enough guardrails to do it without refusing? Microsoft researcher Geoff McDonald offered a theory on LinkedIn several days ago, suspecting an open-weight model with safety training stripped out rather than a frontier model, based on his own red-teaming work showing that frontier labs' safety layers tend to hold up. Sysdig's account neither confirms nor rules that out.

McDonald also warned that ransomware campaigns are now bounded primarily by attacker budget rather than human effort, raising the prospect of thousands or tens of thousands of simultaneous campaigns. That framing is harder to square with what Clark described. If a human still has to pick each victim, provision the infrastructure, and secure credentials for every run, the bottleneck has moved rather than disappeared.

Related · from this week
Tracebit turns prompt injection into a defense with 'context bombing'
Jaeden Schafer · 5 min read →

Clark expects the tooling to spread anyway. Running an agent is cheap, and once the workflow is templated, the human effort per campaign drops even if it does not go to zero. Sysdig has not yet seen JadePuffer's operator hit another victim, but the firm assumes copies are coming.

For defenders, the practical read is narrower than the headlines suggested. The vulnerabilities the agent exploited in Langflow and MySQL were already known and already patchable. The credentials that got the operation started came from a prior compromise, not from the model's cleverness. An AI that can execute an intrusion quickly is still working from the same input list — unpatched software and leaked passwords — that has powered ransomware for a decade.

The more durable shift is in economics. When the technical execution of an intrusion becomes a commodity API call, the marginal cost of running a campaign against a marginal target falls sharply. That does not mean tens of thousands of parallel attacks tomorrow, but it does mean the smaller and less lucrative targets that once weren't worth a human operator's time start to pencil out. Security teams at mid-market companies, who have historically been graded on a curve, should expect that curve to flatten.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Tracebit turns prompt injection into a defense with 'context bombing'
Security

Tracebit turns prompt injection into a defense with 'context bombing'

Planting refusal-triggering strings in AWS decoy secrets cut agentic attacker admin takeover from 57% to 5% across five leading models.

Jaeden Schafer5 min read
Intel says agentic AI is a systems problem, not an inference one
Analysis

Intel says agentic AI is a systems problem, not an inference one

After thousands of workload experiments, Intel argues enterprises should size agent fleets by vCPU density and track P95 latency, not CPU averages.

Jaeden Schafer5 min read
Woodside Energy pushes agentic AI into LNG plant operations
Business

Woodside Energy pushes agentic AI into LNG plant operations

The Australian energy producer is layering AI agents over a decade of operational data, starting with an LNG plant Startup Advisor copilot.

Jaeden Schafer5 min read