logo

JadePuffer Returns With Ransomware Designed to Wipe AI Models

ID: 2518935c-f626-5939-943c-0854561a99cc

STIX ID: report--2518935c-f626-5939-943c-0854561a99cc

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

Sysdig Threat Research Team reports that the JadePuffer operator re-used a Langflow CVE-2025-3248 exploit to deploy ENCFORGE, a UPX-packed Go ransomware that deliberately targets ~180 AI/ML model and dataset formats (PyTorch, TensorFlow, SafeTensors, GGUF, FAISS, Parquet, TFRecord, NumPy, LoRA, etc.). The adversary performed real-time remediation when delivery inside the container failed by iterating Python payloads through the RCE to use a mounted Docker socket, spawning a privileged escape container, copying the locker via procfs and executing host-level encryption; ENCFORGE uses AES-256-CTR with RSA-2048 key exchange, kills locking processes, and self-deletes. Sysdig observed no data exfiltration or leak site (destructive-only ransomware) and estimated model-rebuild costs of $75k–$500k per model, highlighting high impact on ML production environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.