Act
archived
ENCFORGE Ransomware Targets AI Infrastructure via Langflow RCE
- Engineer — Act: Active exploitation of a Langflow RCE is being used to deploy Go-based ransomware that encrypts model weights, vector indexes, and training data. If you run Langflow, patch or network-isolate it immediately and review Sysdig’s full JADEPUFFER report for host-level IOCs to audit your AI infrastructure.
- SOC/IR — Act: A named operator (JADEPUFFER) has been caught in a second confirmed intrusion deploying ENCFORGE ransomware via Langflow; pull Sysdig’s IOC set and hunt for anomalous Go process execution or bulk file encryption activity on hosts running Langflow or adjacent AI pipeline components.
- Leader — Learn: ENCFORGE is the first documented ransomware purpose-built to destroy AI model assets rather than generic data, signaling that AI infrastructure is becoming a distinct extortion target worth adding to the risk register ahead of broader AI investment discussions.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.