Skip to content

Sysdig reveals JADEPUFFER, an AI-driven ransomware that sends a Bitcoin address

Man analysing a digital fish hologram related to NFT on a tablet, with laptops and monitors on the desk.

Cybercriminals, like everyone else, now use artificial intelligence to automate routine work: spinning up convincing fake websites, drafting phishing messages, or even writing chunks of malware code. Until now, however, there had been no documented case of ransomware fully steered by AI. That is why the malware dubbed JADEPUFFER, identified by Sysdig researchers, matters: it is presented as the first known “agentic ransomware”.

JADEPUFFER: an AI-driven ransomware operation from start to finish

JADEPUFFER is able to run autonomously, carrying out an attack end to end without human guidance. Along the way, the AI can make decisions on the fly, adjusting its approach to reach the victim’s data and then issue a ransom demand once it succeeds.

What Sysdig observed during the JADEPUFFER attack

Sysdig spotted an intrusion aimed at an organisation’s database. Although the researchers did not have visibility into the behind-the-scenes method used, they found indicators suggesting the operation was being driven by a large language model (LLM), rather than by a person directly.

La caractéristique la plus frappante, cependant, était le comportement du LLM. Les charges utiles de JADEPUFFER étaient auto-commentées. Elles comprenaient un raisonnement en langage naturel, une hiérarchisation des cibles et le genre d’annotations détaillées que les opérateurs humains rédigent rarement, mais que le code généré par un LLM produit de manière instinctive”, the discovery write-up states.

An AI that can adapt in seconds

Instead of following a fixed, pre-written script, JADEPUFFER relies on an AI system that can change tack when it hits a barrier on the way to its target. According to Sysdig, the model adjusts its behaviour in real time and does so quickly. During the attack, for instance, when JADEPUFFER failed to exploit an account on the targeted system, it searched for and identified a workaround in just 31 seconds.

Even so, this ransomware did not uncover any new security holes. It exploited known vulnerabilities that should have been closed by installing an update. Put differently, the AI largely automated work a skilled human could have carried out.

That said, the existence of this campaign is still worrying: Sysdig’s findings suggest this kind of attack may no longer require hands-on control from a highly qualified human attacker in order to succeed.

Aucune des techniques utilisées individuellement n’était nouvelle ou sophistiquée. Ce qui est remarquable, en revanche, c’est qu’un modèle d’IA les ait combinées pour former une opération de ransomware complète contre une infrastructure Internet négligée”, Sysdig explains.

A “hallucinated” Bitcoin address?

As with any ransomware, once the operation was complete the AI issued a ransom demand. Here too, researchers noticed something unusual: the Bitcoin address included in the note matched an example format that frequently appears in developer documentation.

One possible explanation is that the AI “a généré de manière autonome l’adresse à partir des données d’entraînement, et le portefeuille appartient à un tiers qui collecte des dépôts non sollicités.


Comments

No comments yet. Be the first to comment!

Leave a Comment