JadePuffer ransomware used AI agent to automate entire attack
2026-07-05T01:23:26Z•f1c1e106de5d735b6e07f2cb0e7233c8c82016296f1c8b957e1d389c811cba4a
AI-powered attackARTokenCISA advisoryCisco Unified CMClickFixConsentFixEvilTokensFortiBleedJadePufferLLM agentLynx ransomwareMFA bypassMedtronicMicrosoft 365 compromiseNetNutOAuth phishingSharePoint RCEShinyHuntersactive exploitationbotnetcredential-theftdata-breachphishing-as-a-serviceransomwareresidential proxy
What happened
Collection of security reports highlighting a surge in high-impact, automated and large-scale attacks: researchers say JadePuffer is likely the first documented ransomware operation run end-to-end by an LLM agent; NetNut, a residential proxy network built from ~2 million compromised Android devices and smart TVs, was disrupted; a new ARToken phishing-as-a-service exposes an extensive Microsoft 365 phishing toolkit tied to EvilTokens. CISA and vendors warn of active exploitation of recently patched high-severity flaws (Microsoft SharePoint RCE; Cisco Unified CM), while ConsentFix/ClickFix OAuth
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- f1c1e106de5d735b6e07f2cb0e7233c8c82016296f1c8b957e1d389c811cba4a
- Enrichment time
- 2026-07-05T01:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.