logo

JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware

ID: 2723bdaa-a059-58d3-92ad-dbaa8c408239

STIX ID: report--2723bdaa-a059-58d3-92ad-dbaa8c408239

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-21

...
...

JadePuffer, an actor leveraging autonomous AI agents, has developed EncForge, a ransomware tool engineered to discover, exfiltrate, and encrypt AI assets (model checkpoints, training datasets, vector DBs and MLOps artifacts). EncForge uses modern cryptography and a double-extortion model, enabling rapid, scalable attacks against poorly backed-up AI infrastructure; the report outlines indicators (ENCFORGE_README.txt, appended file markers), detection signals, affected sectors, and concrete hardening and incident-response recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.