First Autonomous LLM Ransomware: JADEPUFFER

Uvcyber pdf 2026-01-11T00:00:00

Abstract

Researchers at Sysdig's Threat Research Team have documented what is assessed to be the first known case of a ransomware operation run entirely by an autonomous large language model, with no human operator directing any phase of the attack. The actor, designated JADEPUFFER, moved through reconnaissance, credential harvesting, lateral movement, data encryption, and extortion as a continuous, self-directed sequence. The significance here is not technical novelty, since the underlying methods are well-worn, but architectural: an AI agent replaced the human element that ransomware has always required.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD