New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
A new ransomware variant called ENCFORGE has emerged, specifically targeting AI infrastructure components like model weights and training datasets. This malware is being deployed by the JADEPUFFER threat actor following exploitation of an unpatched vulnerability in Langflow versions prior to 1.3.0. The flaw, CVE-2025-3248, allows remote code execution without authentication and remains a high-risk issue with a CVSS score of 9.8. Researchers at Sysdig discovered that attackers are using this entry point to deploy ENCFORGE, which encrypts AI-specific file formats such as PyTorch checkpoints, Hugging Face models, and FAISS indexes. The ransomware avoids exfiltrating data but focuses on rendering AI assets unusable, potentially costing organizations hundreds of thousands in recovery costs. Immediate mitigation includes upgrading Langflow to version 1.9.1 or later and securing Docker socket access.