JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
ID: 51785841-16d6-53e4-a5da-65ac9d057e56
STIX ID: report--51785841-16d6-53e4-a5da-65ac9d057e56
Feed Name: GBHackers
JADEPUFFER exploited a missing-authentication bug in a Langflow endpoint (CVE-2025-3248) to gain unauthenticated Python execution, harvest credentials, move laterally, and deploy a purpose-built Go ransomware named ENCFORGE that targets AI/ML artifacts (model weights, checkpoints, vector indexes, training data) for destructive, single‑extortion attacks; the report includes technical analysis of the ransomware’s hybrid AES‑256‑CTR/RSA‑2048 scheme, container escape and deployment techniques, attack TTPs, and indicators of compromise (file hashes and artifacts).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
