type: entity ยท created: 2026-07-21 ยท updated: 2026-07-21 ยท tags: [ransomware, loader] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: false
ENCFORGE โ AI-Focused Go Ransomware
ENCFORGE is a compiled Go ransomware specifically designed to encrypt AI infrastructure files. Discovered by Sysdig researchers in July 2026, it is deployed by the Jadepuffer AI-agent-driven operator.
Capabilities
- Encrypts model weights (AI/ML model files)
- Encrypts vector indexes (vector database files)
- Encrypts training datasets (structured/unstructured training data)
- Targets other AI infrastructure files (configuration, pipeline artifacts)
- Compiled in Go suggesting cross-platform capability
Distribution
- Deployed via Jadepuffer attacks on Langflow servers
- Entry vector: CVE-2025-3248 (CVSS 9.8), a critical Langflow vulnerability
- Second attack on same Langflow server linked to same operator
Significance
ENCFORGE represents a targeted evolution in ransomware โ moving beyond general-purpose encryption to specifically target the crown jewels of AI operations: trained model weights and training data. This is more destructive than general ransomware for organisations running AI workloads, as model weights may be irreplaceable if backups do not exist.
Related Pages
- Jadepuffer โ The threat actor deploying ENCFORGE
- Nadmesh Botnet โ Go-based botnet scanning for exposed AI services