FILTERING BY: CLEAR FILTER

ENCFORGE Ransomware: JADEPUFFER Sabotage Campaign Targeting Langflow and AI Infrastructure

The threat actor JADEPUFFER has deployed a novel ransomware strain, ENCFORGE, specifically engineered for the targeted destruction of artificial intelligence infrastructure rather than traditional financial extortion. Unlike standard ransomware, ENCFORGE focuses on corrupting high-value AI model weights (.bin, .safetensors, .pth) and disrupting orchestration layers such as Langflow. The malware utilizes agentic behavior to perform autonomous lateral movement within AI clusters, specifically targeting GPU-accelerated compute environments and vector databases. This "sabotage-ware" approach prioritizes the destruction of intellectual property and model integrity over ransom collection, presenting a critical risk to LLM supply chains and AI-driven production environments.


LINK COPIED TO CLIPBOARD