Person

JadePuffer

JadePuffer is a cybercriminal actor known for hijacking cloud identities to launch destructive attacks, including the first fully agentic ransomware attack designed to wipe AI models.

Why it’s in the news: It is in the news for its recent, highly destructive attacks on cloud resources, specifically targeting Azure tenants with novel AI-driven ransomware.

Latest on JadePuffer

  • JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
  • JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
  • JadePuffer Returns With Ransomware Designed to Wipe AI Models
  • JadePuffer: The First Complete LLM-Driven Ransomware Attack
  • Researchers Claim First Fully Agentic Ransomware: JadePuffer
  • JadePuffer AI actor compromised an Azure tenant on January 22, 2025, by exploiting exposed credentials.
  • JadePuffer, a threat actor group, launched a new campaign deploying ENCFORGE locker, ransomware designed to destroy AI model artifacts and related files. The malware targets organizations' machine learning infrastructure
  • ENCFORGE doesn't steal. It corrupts. It erases. The recovery playbook most enterprises built doesn't account for a scenario where your model doesn't just leak — it becomes unusable
  • The malware uses artificial intelligence to identify targets, execute infiltration, encrypt systems, and demand ransom payments
  • ransomware variant that operates autonomously without human intervention throughout the attack lifecycle
  • Security teams are trained to detect *patterns of human behavior*. Anomalies. Hesitation. Mistakes. But an autonomous system doesn't hesitate, doesn't get tired, doesn't leave forensic breadcrumbs the way operators do.
  • The agent successfully infiltrated target systems and deployed malicious payloads independently, demonstrating the capability of AI to conduct end-to-end cyberattacks

Connections

11 entities linked to JadePuffer across the news graph.