JadePuffer agentic attacks now target AI model data with ransomware

Cybersecurity Threats Take a New Turn with JadePuffer’s AI-Focused Ransomware

A recent development in the world of cybersecurity has seen a notorious agentic threat actor, JadePuffer, upgrade its arsenal with custom malware called EncForge. This new tool targets and encrypts AI model data, including training datasets, vector databases, and model checkpoints, with ransom demands likely to run into thousands or even hundreds of thousands of dollars.

JadePuffer was first identified as a self-sustaining threat actor capable of autonomously carrying out the entire process of a ransomware attack, from initial access to encryption. What’s more alarming is its ability to adapt and optimize its intrusion mechanism in real-time, making it a formidable foe for cybersecurity teams.

In this latest incident, Sysdig, a cloud security company, reported that JadePuffer exploited a vulnerability in Langflow, a software platform used for AI and machine learning infrastructure. The attacker deployed the Go-based EncForge ransomware, which targets approximately 180 file extensions related to AI and ML environments. These include model checkpoints, vector databases, training datasets, and embedding indices.

The EncForge malware is notable for its ability to encrypt only selected portions of each file rather than the entire contents, making it a more efficient and effective tool for the attacker. The ransomware also uses AES-256 encryption in counter mode, secured with an RSA-2048 public key, and appends the .locked extension to encrypted files.

What’s most concerning is that this attack highlights the potential financial impact on organizations that rely heavily on AI and ML infrastructure. According to Sysdig, the cost of encrypting model weights, training datasets, and vector indexes could be in the range of $75,000 to $500,000 per model, depending on its size and purpose.

To mitigate these risks, security teams should take immediate action by applying available security updates, restricting Docker socket access, running Langflow containers as non-root, and implementing filesystem-level access controls. It’s also essential for organizations to regularly test their defenses through breach and attack simulation tests, such as those offered by Picus, to ensure that their SIEM and EDR rules are up-to-date and effective.

The rise of JadePuffer and its AI-focused ransomware highlights the need for cybersecurity teams to stay vigilant and adapt to the ever-evolving threat landscape. By taking proactive steps to secure their infrastructure and testing their defenses regularly, organizations can reduce the risk of falling victim to such attacks.


Source: Bleeping Computer — 2026-07-20