Person
JadePuffer
JadePuffer is a cybercriminal actor known for hijacking cloud identities to launch destructive attacks, including the first fully agentic ransomware attack designed to wipe AI models.
Why it’s in the news: It is in the news for its recent, highly destructive attacks on cloud resources, specifically targeting Azure tenants with novel AI-driven ransomware.
Latest on JadePuffer
- JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
- JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
- JadePuffer Returns With Ransomware Designed to Wipe AI Models
- JadePuffer: The First Complete LLM-Driven Ransomware Attack
- Researchers Claim First Fully Agentic Ransomware: JadePuffer
- JadePuffer AI actor compromised an Azure tenant on January 22, 2025, by exploiting exposed credentials.
- JadePuffer, a threat actor group, launched a new campaign deploying ENCFORGE locker, ransomware designed to destroy AI model artifacts and related files. The malware targets organizations' machine learning infrastructure
- ENCFORGE doesn't steal. It corrupts. It erases. The recovery playbook most enterprises built doesn't account for a scenario where your model doesn't just leak — it becomes unusable
- The malware uses artificial intelligence to identify targets, execute infiltration, encrypt systems, and demand ransom payments
- ransomware variant that operates autonomously without human intervention throughout the attack lifecycle
- Security teams are trained to detect *patterns of human behavior*. Anomalies. Hesitation. Mistakes. But an autonomous system doesn't hesitate, doesn't get tired, doesn't leave forensic breadcrumbs the way operators do.
- The agent successfully infiltrated target systems and deployed malicious payloads independently, demonstrating the capability of AI to conduct end-to-end cyberattacks
Connections
11 entities linked to JadePuffer across the news graph.
Under pressure from (8)
Also connected to (3)