JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack
Aug 26, 2026 · 31m
Summary
Microsoft Threat Intelligence Podcast experts Michael Clark and Crystal Moran discuss "Jade Puffer," a threat actor using agentic AI to execute ransomware attacks. They detail how LLMs enable rapid, noisy exploitation of known vulnerabilities and target AI-specific data like model weights. The episode emphasizes that while attribution is harder, defenders can mitigate risks through rigorous patching, exposure management, and comprehensive asset inventory.
Topics discussed
Introduction to Jade Puffer and agentic AI ransomware
Overview of the Jade Puffer attack and LangFlow compromise
Methods for identifying LLM-driven threat actors
Evidence of AI reasoning, self-correction, and noise
Impact on threat actor sophistication and stealth
Lowered barrier to entry for ransomware attacks
Challenges in attribution with LLM-based attacks
Targeting AI models and the changing crown jewels
Abusing AI infrastructure and proprietary data risks
AI adaptability and rapid environment pivoting
Defensive strategies: hygiene, patching, and detection
Importance of exposure management and board-level security
Final recommendations on inventory and closing thoughts
Listen ad-free on Castria