JadePuffer
Also known as JADEPUFFER
Reports
5
First seen
Jul 2, 2026
Last seen
Jul 13, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Top ATT&CK techniques
T1486 Data Encrypted for Impact ×5T1003 OS Credential Dumping ×4T1190 Exploit Public-Facing Application ×4T1021 Remote Services ×3T1547 Boot or Logon Autostart Execution ×2T1566 Phishing ×2T1041 Exfiltration Over C2 Channel ×2T1555 Credentials from Password Stores ×2T1490 Inhibit System Recovery ×2T1078 Valid Accounts ×1T1053 Scheduled Task/Job ×1T1087 Account Discovery ×1
Indicators
cve ×9domain ×2filename ×1ip_v4 ×1url ×1email ×1bitcoin_address ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High