JadePuffer Deploys EncForge Ransomware Against AI Infrastructure
Langflow is an open-source framework for building large-language-model applications and agent workflows, making its servers a potentially valuable gateway to cloud credentials, model files and vector databases. Sysdig first documented JadePuffer on July 1, 2026, describing it as an agentic threat actor that used AI to automate reconnaissance, credential theft and destructive database extortion. Its shift toward purpose-built attacks on machine-learning assets raises the stakes because production models can require months of work and substantial computing investment to recreate.
Sysdig’s Threat Research Team said on July 20 that JadePuffer had returned to the same Langflow instance and deployed EncForge after exploiting CVE-2025-3248. The UPX-packed ransomware, compiled in Go, targets about 180 file extensions spanning model weights, checkpoints, training datasets and vector indexes. It uses AES-256-CTR and RSA-2048 encryption and renames affected files with a .locked suffix. Sysdig estimated that rebuilding a single production-grade, fine-tuned model could cost between $75,000 and $500,000 in computing resources and engineering work.
All Coverage
1 original reportsThe Backstory
The history behind this eventJadePuffer Exploits AI and Langflow Flaw in Fully Automated Ransomware Attack
Langflow is an open-source platform for building generative AI workflows and agents. Threat-intelligence company Sysdig said hacking group JadePuffer exploited a Langflow vulnerability for initial access, then used an LLM and AI Agent to advance the ransomware attack. The operation marks a shift from human-controlled cyber threats toward autonomous, decision-making “agentic threat actors.”
Sysdig recently disclosed what it described as the first ransomware campaign conducted entirely by an LLM and AI Agent. The agent could identify the victim's environment, troubleshoot execution errors and dynamically rewrite commands based on the results, making the attack highly automated. A July 3 cybersecurity daily report also warned of a trend toward large-scale automated attacks. The number of victims, losses and ransom demands have not been disclosed.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.