logo

JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data

ID: 51785841-16d6-53e4-a5da-65ac9d057e56

STIX ID: report--51785841-16d6-53e4-a5da-65ac9d057e56

Feed Name: GBHackers

Threat Score
82/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

JADEPUFFER exploited a missing-authentication bug in a Langflow endpoint (CVE-2025-3248) to gain unauthenticated Python execution, harvest credentials, move laterally, and deploy a purpose-built Go ransomware named ENCFORGE that targets AI/ML artifacts (model weights, checkpoints, vector indexes, training data) for destructive, single‑extortion attacks; the report includes technical analysis of the ransomware’s hybrid AES‑256‑CTR/RSA‑2048 scheme, container escape and deployment techniques, attack TTPs, and indicators of compromise (file hashes and artifacts).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.