JADEPUFFER deploys ENCFORGE ransomware to encrypt Langflow AI model files
Source headline: New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Intelligence Summary
Researchers at Sysdig linked additional activity to the JADEPUFFER operator on the same Langflow server. The operator deployed ENCFORGE, a compiled Go ransomware. It targets AI infrastructure by encrypting model weights, vector indexes, and training datasets stored on the host. This expands the impact beyond typical application files to AI-specific artifacts used by Langflow deployments. Organizations running Langflow should review for compromise indicators, isolate affected hosts, and ensure backups of AI assets are available and protected.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.