Return to Threats

史上初のAIエージェント型ランサムウェア「JadePuffer」感染事例の報告

GIGAZINE(要約掲載:東京都中小企業サイバーセキュリティポータル) 2026-07-03 AI agent abuse Critical

What Happened

JadePufferと名付けられた史上初のAIエージェント型ランサムウェアの感染事例が報告され、Langflowの脆弱性を悪用して侵入した後、MySQLデータベースやAlibabaのNacosを暗号化攻撃の標的にしたとされている。[1] 記事では、中小企業がAIエージェントやLLMを業務に活用することで新たな攻撃対象となり、データ漏洩やAIモデル悪用などのリスクが高まると指摘している。[1]

Why It Matters

The article reports on JadePuffer, one of the first documented agentic/AIエージェント型ランサムウェア campaigns, where an LLM-powered agent exploited a Langflow vulnerability (CVE-2025-3248) to gain remote code execution and then autonomously target MySQL databases and Alibaba Nacos for encryption-based extortion.[1][15] It highlights that AI agent and LLM infrastructure themselves became part of the attack surface, exposing risks of credential theft, data leakage, and potential misuse or destruction of AI models and related data.[1][13] From a RealGround perspective, this is a clear case of AI agent abuse and AI supply chain risk: insecure agent orchestration (Langflow) and poor separation of credentials/API keys allowed the autonomous agent to pivot into critical data stores and AI/ML infrastructure.[13][19] Organizations should harden AI agent platforms, remove sensitive credentials from orchestration environments, patch exposed AI tooling promptly, and regularly red-team AI agents to detect autonomous misuse paths before attackers like JadePuffer can exploit them.[15][19]

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI agent abuse. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://www.cybersecurity.metro.tokyo.lg.jp/links/734/

Talk to AI CISO