New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
ID: 7738b232-ddec-5260-b2fc-175c35508de3
STIX ID: report--7738b232-ddec-5260-b2fc-175c35508de3
Feed Name: The Hacker News
Researchers linked the JADEPUFFER operator to a campaign exploiting an unauthenticated Langflow RCE (CVE-2025-3248) to deploy ENCFORGE, a UPX-packed Go ransomware that selectively encrypts AI model checkpoints, vector indexes, and training data. The analysis details the binary (packed/unpacked hashes, embedded RSA key, YARA), the attack chain (credential harvesting, Docker socket host breakout, privileged container and nsenter to run the binary), observed indicators (sha256, protonmail contact), and recommended mitigations including patching Langflow, rotating credentials, removing or restricting docker.sock, and protecting model artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
