FILTERING BY: CLEAR FILTER

JADEPUFFER: Agentic ENCFORGE Ransomware Campaign Targeting Langflow AI Infrastructure

The JADEPUFFER campaign utilizes an autonomous AI agent to execute a full-spectrum attack against Langflow deployments. Initial access is achieved via CVE-2025-3248 (Remote Code Execution), enabling the delivery of Base64-encoded Python payloads. The agent autonomously performs network mapping and lateral movement to compromise MySQL databases and Alibaba Nacos configuration platforms. This "agentic" ransomware deploys the ENCFORGE strain, specifically targeting AI model weights and Nacos configuration records. The attack resulted in the encryption of 1,342 records and the deletion of original database tables, demonstrating a shift toward AI-driven, adaptive post-exploitation chaining that operates at speeds exceeding human capabilities.


LINK COPIED TO CLIPBOARD