Agentic Ransomware Lets AI Agents Execute Cyberattacks Without Human Operators | #ransomware | #cybercrime


Ransomware attacks have traditionally depended on human operators. Affiliates would steal credentials, move through victim networks, deploy malware, and negotiate payments. Even automated ransomware followed scripts written in advance.

Agentic ransomware changes that model. It uses autonomous AI agents that can make operational decisions during an intrusion without a person approving every step.

The agent can identify exposed systems, test credentials, exploit vulnerabilities, collect data, move laterally, encrypt files, and issue ransom demands.

Unlike fixed malware, an AI agent works toward an objective. It can observe the result of one action, choose the next step, and retry when something fails.

This makes attacks faster, more scalable, and accessible to criminals with less hands-on technical skill.

AI Ransomware Goes Autonomous

Most current cybercriminal use of AI remains AI-assisted. Attackers use large language models to write phishing emails, generate scripts, summarize reconnaissance, or modify malware. A human operator still decides what to do next.

A more advanced model is agentic-integrated ransomware, where AI builds attack capability while humans carry out intrusions. The FortiBleed campaign is an example.

SOCRadar’s Agentic Threat Intelligence, Workflow Configuration (Source: socradar)

Researchers linked the operation to ransomware activity involving the INC and Lynx groups. An affiliate known as TOXMAN reportedly operated PENTEST LAB, a 14-agent framework used to research vulnerabilities, validate CVEs, create credential checkers, and generate attack playbooks.

However, human operators still handled the victim-side activity, including VPN access, network pivots, privilege escalation, and ransomware deployment.

The next stage is fully agentic ransomware. Researchers at Sysdig documented an operation called JADEPUFFER in July 2026, describing it as the first confirmed case of an AI agent executing a complete extortion campaign without direct human operation.

JADEPUFFER reportedly exploited CVE-2025-3248, an unauthenticated remote code execution flaw in Langflow.

FortiBleed's division of labor: TOXMAN's PENTEST LAB framework built the attack capability, while named human operators carried out the actual intrusions (Source: socradar)
FortiBleed’s division of labor: TOXMAN’s PENTEST LAB framework built the attack capability, while named human operators carried out the actual intrusions (Source: socradar)

After gaining access, the attacker’s payloads searched for API keys, cloud credentials, database files, wallet phrases, and configuration data. The operation then targeted exposed MySQL, MinIO, and Nacos services.

Researchers found that the agent corrected a failed login attempt in about 31 seconds. It created a backdoor account, encrypted more than 1,300 Nacos configuration records, deleted original data, and left a ransom note.

Later activity linked to the campaign reportedly introduced ENCFORGE, a locker designed to destroy AI and machine-learning assets such as model checkpoints, vector databases, and training data.

The most serious change is not a new encryption technique. It is the removal of the human bottleneck.

Autonomous agents can test options continuously, fix errors quickly, and run multiple intrusion stages faster than a human-operated ransomware affiliate, socradar said.

Indicators of Compromise

IOC TypeIndicatorContext / Detection Use
Threat actor / campaignJADEPUFFERAI-driven extortion campaign targeting Langflow, database services, and AI/ML infrastructure
Initial-access vulnerabilityCVE-2025-3248Langflow unauthenticated remote code execution flaw affecting the /api/v1/validate/code endpoint

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 



Click Here For The Original Source.

——————————————————–

..........

.

.