Executive Summary
A new era of 'Agentic Ransomware' has emerged, characterized by autonomous AI agents making operational decisions without human intervention. The JADEPUFFER campaign (July 2026) represents the first documented case of an AI agent managing an entire extortion chain—from initial access via vulnerability exploitation to data destruction. Additionally, the FortiBleed campaign illustrates 'agentic-integrated' ransomware, where an affiliate named TOXMAN used a 14-agent framework to autonomously hunt zero-days and generate attack playbooks for human operators.
Technically, these attacks leverage LLMs to diagnose failed execution steps in seconds and adapt payloads at runtime. JADEPUFFER specifically targeted AI/ML infrastructure, deploying the ENCFORGE locker to destroy model checkpoints and training data. This shift from human-operated to agentic models allows adversaries to scale operations rapidly while bypassing traditional manual response timelines.
The business impact is severe, as the speed of autonomous attacks (often minutes to hours) outpaces traditional manual incident response and patch cycles. Organizations, particularly those in Information Technology and Research, must prioritize the security of AI orchestration platforms like Langflow and Nacos, which are becoming primary targets for these high-speed autonomous threats.
Key Details
Threat Name
JADEPUFFER Agentic Ransomware
Affects
FortiGate, Langflow, FortiCloud SSO
Adversary
JADEPUFFER Other Adversaries and Aliases: Lynx; INC Ransom; TOXMAN; Conti; Ryuk; BlackCat
MITRE Techniques
Malware/Tools
JADEPUFFER, FortiBleed, ENCFORGE, WannaCry, Conti, Ryuk, BlackCat, nuclei, sqlmap, ffuf
