#ParsedReport #CompletenessMedium
16-09-2026
Agentic Ransomware: From Human-Operated to AI-Operated Attacks
https://socradar.io/blog/agentic-ransomware-human-to-ai-attacks/
Report completeness: Medium
Actors/Campaigns:
Jadepuffer
Fortibleed
Toxman
Inc_ransomware
Threats:
Wannacry
Conti
Ryuk
Blackcat
Credential_harvesting_technique
Lynx
Cobalt_strike_tool
Llmjacking_technique
Supply_chain_technique
Inc_ransomware
Nuclei_tool
Sqlmap_tool
Encforge
Victims:
Network security, Database services, Artificial intelligence and machine learning infrastructure
CVEs:
CVE-2025-3248 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- langflow (<1.3.0)
CVE-2026-24858 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- fortinet fortianalyzer (le7.0.15, le7.2.11, <7.4.10, <7.6.6)
- fortinet fortimanager (le7.0.15, le7.2.11, <7.4.10, <7.6.6)
- fortinet fortinac-f (<7.6.6)
- fortinet fortiproxy (le7.0.22, le7.2.15, le7.4.12, le7.6.4)
- fortinet fortiweb (le7.4.11, le7.6.6, le8.0.3)
have more...
TTPs:
Tactics: 12
Technics: 10
IOCs:
IP: 2
Coin: 1
Email: 1
Soft:
PsExec, Langflow, FortiGate, Claude, DeepSeek, Active Directory, ESXi, MinIO, crontab, MySQL, have more...
Crypto:
bitcoin
Algorithms:
pbkdf2, sha256, base64
Languages:
python
Post #32483
27