JADEPUFFER: The AI Malware With No Human in the loop

Infographic 2026

Find Threat Talks on

What if AI stopped being the assistant to cybercriminals and became the attacker itself? That’s no longer hypothetical.

 

JADEPUFFER is the first documented case of ransomware run entirely by an AI agent. It broke into a production database, hit a wall mid-attack, and found another way in within 31 seconds, faster than most human pen testers can react.

Rob Maas, Field CTO at ON2IT, sits down with Yuri Wit, SOC DevOps Engineer at ON2IT, to trace how AI-assisted attacks turned into AI-run ones. From PromptLock’s proof of concept to PromptSteal’s real-world payloads and now JADEPUFFER’s fully autonomous attack, the pattern is the same: attackers are handing the decisions to the model. Here’s what it means for your SOC, and what you can still do about it.

 

What you’ll learn

  •  From assisted to autonomous.** AI-written phishing and deepfakes were only the opening move.
  • Why 31 seconds matters.** JADEPUFFER’s AI agent pivoted around a blocked path faster than any human team could react.
  • Zero Trust ages well.** Protect Surfaces limit what agentic malware can reach once it’s inside.

 

Your cybersecurity experts

Rob Maas

Rob Maas

Field CTO
ON2IT

Jelle Konings

Yuri Wit

Security Reasearcher
ON2IT

Episode details

Yuri lays out a three-tier taxonomy that maps directly onto how fast a defender has to react:

 AI-assisted attacks (deepfakes, phishing, AI-written code) where a human still runs the show, AI-runtime malware like PromptLock and PromptSteal that queries a large language model mid-attack, and fully agentic malware like JADEPUFFER that plans, executes, and pivots with no human in the loop and no defined scope.

 PromptLock itself turned out to be an academic proof of concept rather than a live attack, complete with a Bitcoin address tied to Bitcoin’s creator that researchers believe was a placeholder. It’s a reminder that proof-of-concept and real attack aren’t always easy to tell apart from the outside.

 The economics matter here. Attackers are unlikely to call frontier models directly. It is not cost efficient, and it leaves a trail. What Rob and Yuri expect instead is a move toward locally hosted, open-source models that attackers control directly, effectively becoming their own command-and-control infrastructure. That changes what “watch your egress traffic” even means for a defender.

 JADEPUFFER is the sharpest example so far, and the first one researchers aren’t calling a proof of concept. The AI agent broke into an internet-facing target, harvested credentials, pivoted to a production database, hit a wall, and found another way in within 31 seconds, then encrypted the target and left a ransom note. No human ran any of those steps.

 The strategic shift both guests land on: static detection weakens as attacks improvise in real time, and behavioral detection is inherently reactive: something has to happen before it can be observed. The one lever that holds up regardless of attacker speed is limiting the blast radius: define your Protect Surfaces, segment around them, and assume something eventually gets past the outer layer.

Infographic 2026

Get your Hacker T-shirt

Join the treasure hunt!

Find the code within this episode and receive your own hacker t-shirt for free.

1 + 11 =

Christmas Hacker