Protect.Computer
NEWS

Ransomware Group Uses AI to Run Its Own Attacks

· 0 min read · Malicious byte Data hijack
Ransomware Group Uses AI to Run Its Own Attacks

Security researchers at Sysdig have uncovered a ransomware operation called JadePuffer that uses a fully autonomous AI agent to carry out attacks from start to finish — no human hacker required. The AI conducts reconnaissance, steals credentials, moves laterally through networks, and finally encrypts files entirely on its own. In one recorded sequence, when a login attempt failed, the AI diagnosed the problem and found a working fix in just 31 seconds.

The attackers gained their initial foothold through a known vulnerability (CVE-2025-3248) in Langflow, an AI development tool that was patched in April 2025. Once inside, the AI agent took control of database servers and encrypted more than a thousand configuration files. While this specific campaign targeted developer-facing cloud infrastructure rather than home computers, it marks an important turning point: AI-powered attacks can run faster, scale larger, and adapt in real time in ways that human-operated campaigns cannot — and that capability will eventually be pointed at a wider range of targets.

Sources

Related reading