FILTERING BY: CLEAR FILTER

ENCFORGE Ransomware: JADEPUFFER Targets Langflow and AI Infrastructure

The JADEPUFFER agentic threat actor has deployed ENCFORGE, a specialized Go-based ransomware designed to disrupt the artificial intelligence lifecycle. The attack chain initiates via Remote Code Execution (RCE) within Langflow servers, followed by privilege escalation through Docker daemon exploitation to gain access to the underlying host filesystem. Unlike generic ransomware, ENCFORGE specifically targets high-value AI assets, including model weights, vector indexes, and training datasets. This specialized targeting aims to destroy proprietary intellectual property and disable Retrieval-Augmented Generation (RAG) capabilities, representing a critical shift toward AI-centric industrial sabotage and data destruction.


LINK COPIED TO CLIPBOARD