# JadePuffer's New Ransomware Threatens AI Infrastructure with ENCFORGE

*Published July 26, 2026*
*Source: [https://www.news4hackers.com/jadepuffer-returns-with-new-ransomware-targeting-ai-models-and-infrastructure/](https://www.news4hackers.com/jadepuffer-returns-with-new-ransomware-targeting-ai-models-and-infrastructure/)*

## Executive Summary

JadePuffer has launched a new ransomware attack using a variant called ENCFORGE, targeting AI and ML infrastructure by encrypting critical components like model checkpoints and datasets. This attack highlights the vulnerabilities in AI systems, emphasizing the need for robust security measures to protect valuable AI assets.

## Article

The notorious threat group JadePuffer has surfaced again, this time wielding a new ransomware variant known as ENCFORGE. This sophisticated tool is engineered to specifically target the infrastructure supporting artificial intelligence and machine learning applications. Building on previous tactics, JadePuffer has intensified its focus on AI assets, employing ENCFORGE to encrypt around 180 different file types. Key targets include model checkpoints, vector databases, and training datasets, which are crucial to AI and ML systems.

The cybersecurity firm Sysdig recently shed light on this attack, which began by exploiting a vulnerability in the Langflow framework, an open-source tool used for constructing AI agents and workflows. The attackers initially compromised an internet-facing instance of Langflow, which led them to a production server. Through this breach, they encrypted a MySQL database and an Alibaba Nacos configuration service. Although data theft has not been confirmed, the attackers' use of an AI-driven agent is notable for its speed and precision in identifying and exploiting vulnerabilities.

The deployment of ENCFORGE represents a significant escalation in ransomware tactics. The tool not only encrypts files but also targets AI/ML environments with precision. Sysdig's Michael Clark reported that the attackers revisited the compromised Langflow instance to deploy ENCFORGE, aiming to disrupt AI model development and deployment. The financial implications are severe, with recovery costs for encrypted models ranging from $75,000 to $500,000.

The attack methodology involved extracting cloud provider credentials and API tokens to access internal systems, and ENCFORGE was successfully deployed after overcoming initial setbacks. Sysdig recommends several measures to mitigate such risks, including addressing known vulnerabilities, restricting Docker socket access, and maintaining offline backups of vital AI model artifacts. The integration of AI agents in these attacks adds a new layer of complexity, demanding heightened vigilance from organizations.
