The Agentic AI Threat Cluster: Exploiting Langflow, n8n, and Hermes Agent Frameworks
The cybersecurity landscape is transitioning from human-led AI assistance to autonomous Agentic AI execution, drastically reducing the defender's response window. Threat actors are utilizing open-source frameworks such as Hermes Agent and OpenClaw, combined with reasoning models like DeepSeek, to conduct high-speed, self-correcting attacks. These campaigns target critical infrastructure and software including Langflow, n8n, and Citrix NetScaler through automated metadata scraping (OAuth/OIDC), prompt-based safety bypasses, and real-time exploitation sourcing. This shift enables unprecedented operational tempo, where AI-driven agents can diagnose and remediate payload errors in seconds, facilitating rapid credential attacks and data exfiltration across government and enterprise networks.
JADEPUFFER: Agentic ENCFORGE Ransomware Campaign Targeting Langflow AI Infrastructure
The JADEPUFFER campaign utilizes an autonomous AI agent to execute a full-spectrum attack against Langflow deployments. Initial access is achieved via CVE-2025-3248 (Remote Code Execution), enabling the delivery of Base64-encoded Python payloads. The agent autonomously performs network mapping and lateral movement to compromise MySQL databases and Alibaba Nacos configuration platforms. This "agentic" ransomware deploys the ENCFORGE strain, specifically targeting AI model weights and Nacos configuration records. The attack resulted in the encryption of 1,342 records and the deletion of original database tables, demonstrating a shift toward AI-driven, adaptive post-exploitation chaining that operates at speeds exceeding human capabilities.
Agentic AI Ransomware Operations via Langflow JADEPUFFER
The JADEPUFFER campaign marks a shift toward autonomous, agentic ransomware operations utilizing the Langflow orchestration framework to execute end-to-end attack chains. By leveraging LLM reasoning for real-time decision-making, the attacker weaponized Langflow's tool-calling capabilities to automate reconnaissance, credential harvesting, and lateral movement after gaining initial access through vulnerabilities in Nacos. This autonomous agent functioned at "machine speed," identifying target databases and executing exfiltration and encryption without human intervention. The attack highlights a critical vulnerability in low-code AI orchestration tools that allow LLMs to execute arbitrary code and interact with system shells, bypassing traditional heuristic detections.