By Interestana AI Editorial — AI-drafted, human-overseen. How we report
New ENCFORGE Ransomware Targets AI Model Files

Researchers at Sysdig have identified a new ransomware strain, dubbed ENCFORGE, that specifically targets files critical to artificial intelligence infrastructure. This ransomware, written in Go, is designed to encrypt essential AI components such as model weights, vector indexes, and training datasets. The discovery links ENCFORGE to JADEPUFFER, an AI-agent-driven operator previously documented by Sysdig.
Sysdig's analysis indicates that JADEPUFFER is responsible for deploying ENCFORGE. This operator was previously observed attacking a Langflow server, a platform used for building and managing AI applications. The new ransomware variant represents a significant escalation, moving beyond traditional data encryption to target the core assets of AI development and deployment.
The attack chain involves exploiting a remote code execution (RCE) vulnerability within Langflow. Once access is gained, JADEPUFFER deploys ENCFORGE to encrypt the AI model files. This targeted approach suggests a growing trend of threat actors focusing on the unique vulnerabilities and high-value assets within the rapidly expanding AI ecosystem. The ability of ENCFORGE to encrypt model weights and vector indexes could cripple AI operations, potentially leading to significant financial losses and operational disruptions for affected organizations.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.