ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Cybersecurity

JADEPUFFER deploys ENCFORGE ransomware to encrypt Langflow AI model files

Source headline: New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 5 hours ago

Intelligence Summary

Researchers at Sysdig linked additional activity to the JADEPUFFER operator on the same Langflow server. The operator deployed ENCFORGE, a compiled Go ransomware. It targets AI infrastructure by encrypting model weights, vector indexes, and training datasets stored on the host. This expands the impact beyond typical application files to AI-specific artifacts used by Langflow deployments. Organizations running Langflow should review for compromise indicators, isolate affected hosts, and ensure backups of AI assets are available and protected.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#go-malware #langflow #jadepuffer #encforge #ai-ransomware
Original reporting The Hacker News New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Open original source