The Microsoft Threat Intelligence Podcast 8.26.26
Ep 76 | 8.26.26

JADEPUFFER: An End-to-End Agentic-Led Ransomware Attack

Show Notes

In this episode of the Microsoft Threat Intelligence Podcast, we are joined by Sysdig’s Michael Clark and Crystal Morin to discuss JADEPUFFER, one of the first documented cases of an LLM conducting an end-to-end ransomware operation. They break down how the agent, and the direction of a threat actor was identified, how AI is lowering the barrier to entry for ransomware, and why speed and adaptability are changing the threat landscape. Plus, they explore what organizations can do to defend against AI-powered attacks, from basic security hygiene and exposure management to better understanding their growing AI infrastructure. 

In this episode you’ll learn:      

  • How Jade Puffer used an LLM to conduct a ransomware attack 
  • Why agentic AI can make cyberattacks faster and more adaptable 
  • How organizations can better protect their growing AI infrastructure 

Some questions we ask:     

  • How did you determine an LLM was conducting the attack? 
  • What basic security practices are most important against these attacks? 
  • Does AI allow less-sophisticated threat actors to carry out more advanced attacks? 

Resources:  

Read the research on JADEPUFFER 

View Crystal Morin on LinkedIn  

View Michael Clark on LinkedIn  

View Elliot Volkman on LinkedIn  

Related Microsoft Podcasts:                   

Discover and follow other Microsoft podcasts at⁠ ⁠⁠microsoft.com/podcasts   

Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network.