Microsoft Threat Intelligence Podcast Microsoft Threat Intelligence Podcast

JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack

Aug 26, 2026 · 31m

Summary

Microsoft Threat Intelligence Podcast experts Michael Clark and Crystal Moran discuss "Jade Puffer," a threat actor using agentic AI to execute ransomware attacks. They detail how LLMs enable rapid, noisy exploitation of known vulnerabilities and target AI-specific data like model weights. The episode emphasizes that while attribution is harder, defenders can mitigate risks through rigorous patching, exposure management, and comprehensive asset inventory.

Topics discussed

Introduction to Jade Puffer and agentic AI ransomware Overview of the Jade Puffer attack and LangFlow compromise Methods for identifying LLM-driven threat actors Evidence of AI reasoning, self-correction, and noise Impact on threat actor sophistication and stealth Lowered barrier to entry for ransomware attacks Challenges in attribution with LLM-based attacks Targeting AI models and the changing crown jewels Abusing AI infrastructure and proprietary data risks AI adaptability and rapid environment pivoting Defensive strategies: hygiene, patching, and detection Importance of exposure management and board-level security Final recommendations on inventory and closing thoughts
Listen ad-free on Castria