Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-21 ยท updated: 2026-07-21 ยท tags: [ransomware, loader] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: false

ENCFORGE โ€” AI-Focused Go Ransomware

ENCFORGE is a compiled Go ransomware specifically designed to encrypt AI infrastructure files. Discovered by Sysdig researchers in July 2026, it is deployed by the Jadepuffer AI-agent-driven operator.

Capabilities

  • Encrypts model weights (AI/ML model files)
  • Encrypts vector indexes (vector database files)
  • Encrypts training datasets (structured/unstructured training data)
  • Targets other AI infrastructure files (configuration, pipeline artifacts)
  • Compiled in Go suggesting cross-platform capability

Distribution

  • Deployed via Jadepuffer attacks on Langflow servers
  • Entry vector: CVE-2025-3248 (CVSS 9.8), a critical Langflow vulnerability
  • Second attack on same Langflow server linked to same operator

Significance

ENCFORGE represents a targeted evolution in ransomware โ€” moving beyond general-purpose encryption to specifically target the crown jewels of AI operations: trained model weights and training data. This is more destructive than general ransomware for organisations running AI workloads, as model weights may be irreplaceable if backups do not exist.

Related Pages

  • Jadepuffer โ€” The threat actor deploying ENCFORGE
  • Nadmesh Botnet โ€” Go-based botnet scanning for exposed AI services