Ransomware attacks have traditionally relied on human operators. Affiliates would steal credentials, move through victim networks, deploy malware, and negotiate payments. The agent can pinpoint vulnerable systems, test passwords, exploit flaws, gather data, move laterally, encrypt files, and demand ransoms.
AI Ransomware Becomes Autonomous Attackers leverage large language models to craft phishing emails, generate scripts, summarize reconnaissance, or modify malware. A notorious affiliate named TOXMAN is believed to have run PENTEST LAB, a 14-agent framework designed for vulnerability research, CVE validation, credential checks, and attack playbook creation. Researchers at Sysdig documented an operation called JADEPUFFER in July 2026, describing it as the first confirmed instance of an AI agent executing a complete extortion campaign without direct human intervention.
Later activity linked to the campaign reportedly introduced ENCFORGE, a locker designed to destroy AI and machine-learning assets such as model checkpoints, vector databases, and training data. Autonomous systems can test options continuously, fix errors swiftly, and execute multiple intrusion stages faster than a human-operated ransomware affiliate, Socradar claims. Indicators of Compromise IOC Type Indicator Context / Detection Use Threat actor / campaign JADEPUFFER AI-driven extortion campaign targeting Langflow, database services, and AI/ML infrastructure Initial-access vulnerability CVE-2025-3248 Langflow unauthenticated remote code execution flaw affecting the /api/v1/validate/code endpoint Join 16,000+ SOC teams with ANY.RUN to enhance threat investigations and decrease manual workload.












.jpg?width=1280&auto=webp&quality=80&disable=upscale)