ZeroFox Intelligence Brief - JADEPUFFER and the Arrival of Agentic Ransomware Threats
|by Alpha Team

ZeroFox Intelligence Brief - JADEPUFFER and the Arrival of Agentic Ransomware Threats
Product Serial: B-2026-08-10a
TLP:CLEAR
In this ZeroFox Intelligence brief, researchers assess JADEPUFFER, the first documented ransomware operation run end-to-end by an autonomous AI agent, and how agentic ransomware capabilities are likely developing even though packaged, ready-to-use toolkits are not yet available on dark web marketplaces.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Executive Summary
Threat actors have almost certainly crossed a ransomware tradecraft threshold with the first documented end-to-end operation driven by a large language model (LLM) agent. This marks the beginning of a capability shift that is very likely to reshape the affiliate tier of the ransomware ecosystem within the next six to 12 months. While ZeroFox and peer research teams have tracked an explosion of weaponized LLM chatbots and stolen artificial intelligence (AI) credential trade throughout the first half of 2026 on dark web forums and Telegram channels, we have not yet observed packaged agentic-attack toolkits offered for sale. Currently, the payloads autonomous agents produce are unreliable and likely to generate operationally broken extortion demands. ZeroFox predicts that the next attributed agentic ransomware campaign will likely originate from a previously unknown or low-reputation threat actor cluster rather than from a recognized top-10 operator.
Tags: tlp:clear, dark web, threat actor