JadePuffer ransomware used AI agent to automate entire attack

2026-07-05T01:23:26Zf1c1e106de5d735b6e07f2cb0e7233c8c82016296f1c8b957e1d389c811cba4a
AI-powered attackARTokenCISA advisoryCisco Unified CMClickFixConsentFixEvilTokensFortiBleedJadePufferLLM agentLynx ransomwareMFA bypassMedtronicMicrosoft 365 compromiseNetNutOAuth phishingSharePoint RCEShinyHuntersactive exploitationbotnetcredential-theftdata-breachphishing-as-a-serviceransomwareresidential proxy

What happened

Collection of security reports highlighting a surge in high-impact, automated and large-scale attacks: researchers say JadePuffer is likely the first documented ransomware operation run end-to-end by an LLM agent; NetNut, a residential proxy network built from ~2 million compromised Android devices and smart TVs, was disrupted; a new ARToken phishing-as-a-service exposes an extensive Microsoft 365 phishing toolkit tied to EvilTokens. CISA and vendors warn of active exploitation of recently patched high-severity flaws (Microsoft SharePoint RCE; Cisco Unified CM), while ConsentFix/ClickFix OAuth

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
f1c1e106de5d735b6e07f2cb0e7233c8c82016296f1c8b957e1d389c811cba4a
Enrichment time
2026-07-05T01:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.