New ENCFORGE Ransomware Encrypts AI Model Files via Langflow Exploit
Attackers are now targeting AI infrastructure with ransomware that encrypts models and datasets. The campaign leverages a known Langflow RCE vulnerability for initial access.
TL;DR
- ENCFORGE is a new Go-based ransomware targeting AI-specific files like model weights and vector indexes.
- Attackers exploited a remote code execution flaw in Langflow to gain initial access.
- This is the second observed attack by the JADEPUFFER threat actor using similar tactics.
- Victims include systems hosting machine learning models and training data sets.
- Organizations using Langflow should patch immediately and monitor for suspicious file encryption.
Security researchers have identified a novel ransomware strain specifically designed to target artificial intelligence workloads. Dubbed ENCFORGE, this Go-based malware focuses on encrypting high-value AI assets including model weights, vector databases, and training datasets.
The attacks were traced back to the JADEPUFFER threat actor group, which has previously been observed exploiting vulnerabilities in Langflow, an open-source tool used for building AI applications. In this latest campaign, attackers leveraged a known remote code execution (RCE) flaw to gain access before deploying the ransomware across compromised hosts.
This marks a significant evolution in ransomware-as-a-service operations, with cybercriminals increasingly tailoring their tools to impact specialized technology stacks within enterprise environments.
Attack Vector and Initial Access
- JADEPUFFER exploited a remote code execution vulnerability in Langflow servers to gain initial footholds.
- Langflow is widely used for orchestrating AI workflows, making its user base an attractive target for financially motivated attackers.
- Once inside, attackers deployed ENCFORGE ransomware directly onto host filesystems without relying on traditional lateral movement techniques.
- Sysdig researchers confirmed this was the second attack by the same group against Langflow installations within a short timeframe.
Impact on AI Infrastructure
- ENCFORGE selectively encrypts AI-related file types including .pth, .pkl, .bin, and vector index formats.
- Model training datasets and configuration files are also targeted, potentially causing long-term operational disruption.
- Unlike general-purpose ransomware, ENCFORGE avoids common document or image files, focusing exclusively on AI workloads.
- Recovery requires either backups or paying ransoms, both of which pose risks to organizations handling sensitive data.
- Organizations running unpatched versions of Langflow remain at immediate risk of compromise.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.