JadePuffer returns with ransomware built to target AI models and infrastructure
Threat actor JadePuffer has returned with ENCFORGE, a new ransomware specifically designed to attack AI and machine learning infrastructure. This follows an earlier campaign where the group used an AI agent to exploit a known vulnerability (CVE-2025-3248) in Langflow, leading to database encryption and destruction. Researchers have confirmed that the same operator is now deploying ENCFORGE, which targets over 180 file types related to AI models, datasets, and configurations. The ransomware was successfully deployed after initial attempts failed, highlighting the evolving tactics of this threat actor. Experts warn that encrypting production AI models can lead to costly recovery efforts, urging organizations to patch exposed systems and harden their environments.