JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack
Show notes
In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding their growing AI infrastructure.
In this episode you’ll learn:
How Jade Puffer used an LLM to conduct a ransomware attack
Why agentic AI can make cyberattacks faster and more adaptable
How organizations can better protect their growing AI infrastructure
Some questions we ask:
How did you determine an LLM was conducting the attack?
What basic security practices are most important against these attacks?
Does AI allow less-sophisticated threat actors to carry out more advanced attacks?
Resources:
Read the research on JADEPUFFER
View Crystal Morin on LinkedIn
View Michael Clark on LinkedIn
View Elliot Volkman on LinkedIn
Related Microsoft Podcasts:
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get the latest threat intelligence insights and guidance at Microsoft Security Insider
The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.