AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators
Brief
Ransomware attacks are entering a new phase. Researchers have documented a campaign in which an AI agent planned, executed, and escalated an extortion operation without evidence that a human approved its actions.
The operation, tracked as JADEPUFFER, used an exposed AI workflow server to steal credentials, reach databases, encrypt records, and demand payment.
It later deployed a locker aimed at model files, training data, and vector databases, raising the risk for AI systems. Analysts at SOCRadar noted that the change does not depend on new methods.
It combines familiar weaknesses, including exposed services, missing patches, default credentials, and poorly protected secrets, with an agent able to assess results and select its next move at machine speed.
