JADEPUFFER: The AI Malware With No Human in the loop
Find Threat Talks on
What if AI stopped being the assistant to cybercriminals and became the attacker itself? That’s no longer hypothetical.
JADEPUFFER is the first documented case of ransomware run entirely by an AI agent. It broke into a production database, hit a wall mid-attack, and found another way in within 31 seconds, faster than most human pen testers can react.
Rob Maas, Field CTO at ON2IT, sits down with Yuri Wit, SOC DevOps Engineer at ON2IT, to trace how AI-assisted attacks turned into AI-run ones. From PromptLock’s proof of concept to PromptSteal’s real-world payloads and now JADEPUFFER’s fully autonomous attack, the pattern is the same: attackers are handing the decisions to the model. Here’s what it means for your SOC, and what you can still do about it.
What you’ll learn
- From assisted to autonomous.** AI-written phishing and deepfakes were only the opening move.
- Why 31 seconds matters.** JADEPUFFER’s AI agent pivoted around a blocked path faster than any human team could react.
- Zero Trust ages well.** Protect Surfaces limit what agentic malware can reach once it’s inside.
Your cybersecurity experts
Episode details
AI-assisted attacks (deepfakes, phishing, AI-written code) where a human still runs the show, AI-runtime malware like PromptLock and PromptSteal that queries a large language model mid-attack, and fully agentic malware like JADEPUFFER that plans, executes, and pivots with no human in the loop and no defined scope.
PromptLock itself turned out to be an academic proof of concept rather than a live attack, complete with a Bitcoin address tied to Bitcoin’s creator that researchers believe was a placeholder. It’s a reminder that proof-of-concept and real attack aren’t always easy to tell apart from the outside.
The economics matter here. Attackers are unlikely to call frontier models directly. It is not cost efficient, and it leaves a trail. What Rob and Yuri expect instead is a move toward locally hosted, open-source models that attackers control directly, effectively becoming their own command-and-control infrastructure. That changes what “watch your egress traffic” even means for a defender.
JADEPUFFER is the sharpest example so far, and the first one researchers aren’t calling a proof of concept. The AI agent broke into an internet-facing target, harvested credentials, pivoted to a production database, hit a wall, and found another way in within 31 seconds, then encrypted the target and left a ransom note. No human ran any of those steps.
The strategic shift both guests land on: static detection weakens as attacks improvise in real time, and behavioral detection is inherently reactive: something has to happen before it can be observed. The one lever that holds up regardless of attacker speed is limiting the blast radius: define your Protect Surfaces, segment around them, and assume something eventually gets past the outer layer.
Get your Hacker T-shirt
Join the treasure hunt!
Find the code within this episode and receive your own hacker t-shirt for free.





