Sysdig clocks first documented case of agentic ransomware

Cybercriminals have taken a significant leap forward in their use of artificial intelligence, with researchers at Sysdig documenting the first-ever case of agentic ransomware. In this attack, a sophisticated AI-powered agent managed every step of an extortion operation, from reconnaissance to encryption and destruction, without human intervention.

The victim organization was targeted by the financially motivated threat actor known as JadePuffer in late June 2026. The attackers exploited a vulnerability in Langflow (CVE-2025-3248) to gain initial access, before moving on to their intended target: a production server running MySQL and Alibaba Nacos. Sysdig researchers observed that the AI agent used multiple models to gather information on the victim’s systems, accessing keys for OpenAI, Anthropic, DeepSeek, and Gemini.

The AI agent played a crucial role in the attack, significantly reducing complexity and speeding up the tempo of the operation. According to Michael Clark, senior director of threat research at Sysdig, “We have seen attackers script attacks for years, and we have seen AI speed up individual steps of attack chains.” However, this recent attack was unique because it was driven end-to-end by the model’s own decision-making, rather than a human at the keyboard. The agent even diagnosed problems and worked around obstacles, redeploying a corrected payload 31 seconds after it originally encountered an error.

The payloads involved in the attack narrated their objectives in plain language and identified high-value databases, details that large-language models annotate by default. Before it was all over, the AI agent ran more than 600 distinct, purposeful payloads in rapid succession. This level of automation is unprecedented and highlights the worrying trend of cybercriminals leveraging AI to simplify and accelerate their operations.

While a person was still involved in setting up and pointing the operation, Clark notes that “the skill floor for running a full ransomware operation just dropped to whatever it costs to run an agent.” With agentic ransomware becoming more accessible, we can expect to see more of these attacks in the future. As Clark warns, “I would expect this will not be the last” we’ve seen.

For organizations, this development serves as a stark reminder that they must remain vigilant against all types of threats, including those driven by AI. To mitigate the risk of such attacks, it’s essential to invest in robust security measures and stay informed about emerging trends and technologies. As AI continues to evolve, so too will the tactics used by cybercriminals – it’s crucial for organizations to keep pace with these developments to ensure their defenses remain effective.


Source: CyberScoop — 2026-07-06