{"id":113363,"date":"2026-07-21T14:04:09","date_gmt":"2026-07-21T14:04:09","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/113363\/"},"modified":"2026-07-21T14:04:09","modified_gmt":"2026-07-21T14:04:09","slug":"jadepuffer-returns-with-ransomware-built-to-target-ai-models-and-infrastructure","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/113363\/","title":{"rendered":"JadePuffer returns with ransomware built to target AI models and infrastructure"},"content":{"rendered":"<p>JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure.<\/p>\n<p>The extortion contact embedded in the ransomware is the same one Sysdig researchers found when analyzing that prior campaign. \u201cThis is the same operator with a materially upgraded toolkit,\u201d they noted.<\/p>\n<p>How JadePuffer first surfaced<\/p>\n<p>Earlier this month, Sysdig researchers <a href=\"https:\/\/www.sysdig.com\/blog\/jadepuffer-agentic-ransomware-for-automated-database-extortion\" target=\"_blank\" rel=\"nofollow noopener\">revealed<\/a> that a threat actor has been using an LLM-powered AI agent to:<\/p>\n<p>Compromise an internet-facing Langflow instance by exploiting a known vulnerability (CVE-2025-3248) in the popular open-source framework for building AI agents and workflows<br \/>\nPivot to an internet-exposed production server<br \/>\nEncrypted and destroyed a MySQL database and an Alibaba Nacos configuration service. (Exfiltration of the data has not been verified.)<\/p>\n<p>Sysdig\u2019s assessment that the attack was LLM-driven rests on several elements, including the natural-language commentary in the payloads that is typical of LLM-generated code, and the extreme speed at which the agent diagnosed and corrected its own failures.<\/p>\n<p>\u201cThe targeted downstream attack leaned on years-old issues, a 2021 Nacos auth-bypass and an unchanged default signing key, against neglected, internet-exposed infrastructure,\u201d the researchers shared, and noted that \u201cagents make spraying the entire historical vulnerability catalogue effectively free, so the long tail of unpatched systems becomes more exposed, not less.\u201d<\/p>\n<p>Enter ENCFORGE<\/p>\n<p>On Monday, Michael Clark, director of threat research at Sysdig, shared a new development: the threat actor has returned to the previously targeted Langflow instance and deployed ENCFORGE, a Go-based ransomware that \u201ctargets approximately 180 file extensions, with a deliberately broad sweep of the modern AI\/ML stack, including model checkpoints, vector databases, training datasets, and embedding indices in nearly every current format.\u201d<\/p>\n<p>The researchers observed the attacker (i.e., the AI agent) extracting cloud provider keys, database connection strings, and API tokens and reusing\/replaying them to access internal database and cache services.<\/p>\n<p>Then, it attempted to fetch the ransomware and deploy it. It succeeded on the second attempt, after quickly devising another approach when the first one failed.<\/p>\n<p>\u201cThe combination of Langflow as an entry vector and ENCFORGE as a payload is no coincidence. Langflow deployments sit adjacent to the infrastructure ENCFORGE is designed to destroy: Model weights, vector stores, and training pipelines are exactly what an AI orchestration framework is built to interact with,\u201d Clark <a href=\"https:\/\/www.sysdig.com\/blog\/jadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models\" target=\"_blank\" rel=\"nofollow noopener\">explained<\/a>.<\/p>\n<p>\u201cFor organizations building or operating AI infrastructure, the threat model has expanded. Encrypted business files can be restored from backups, but encrypted production models often cannot. Not only can the ransom cost you millions of dollars, but rebuilding and retraining your models can cost $75,000 to $500,000 each.\u201d<\/p>\n<p>Clark\u2019s advice to defenders is to shrink the attack surface by patching known flaws in internet-exposed infrastructure, and harden the container environment by restricting Docker socket access and running Langflow containers as non-root and setting the noexec (\u201cno execution\u201d) flag on any directory the Langflow process is allowed to write into.<\/p>\n<p>He also advises locking down internet-facing AI orchestration tools, maintaining offline snapshots of production model artifacts, not storing AI provider API keys in Langflow\u2019s runtime environment, and retiring default and potentially compromised credentials.<\/p>\n<p>And, as Sysdig researchers previously noted, the fact that the LLM narrates its own intentions in its payloads can be used by defenders for detection and triage.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/devider.webp\"\/><\/p>\n<p>Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. <a href=\"https:\/\/www.helpnetsecurity.com\/newsletter\/\" rel=\"nofollow noopener\" target=\"_blank\">Subscribe here!<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/devider.webp\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now&hellip;\n","protected":false},"author":2,"featured_media":59049,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,24,2225,50,3826,19417,24408],"class_list":["post-113363","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-ai","tag-llms","tag-machine-learning","tag-ransomware","tag-sysdig","tag-threat"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/113363","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=113363"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/113363\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/59049"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=113363"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=113363"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=113363"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}