type: entity ยท created: 2026-07-21 ยท updated: 2026-07-21 ยท tags: [cybercrime-group, ransomware-group] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: false
JADEPUFFER โ AI-Agent-Driven Threat Actor
JADEPUFFER is an AI-agent-driven cybercrime operator that targets AI infrastructure, particularly Langflow servers. The operator has been linked to multiple attacks on the same Langflow deployment, with Sysdig researchers confirming a second attack via the same entry vector.
TTPs
- Entry point: CVE-2025-3248 (CVSS 9.8) โ critical Langflow vulnerability, in CISA's KEV catalog since May 2025
- Target: AI infrastructure โ model weights, vector indexes, training datasets
- Tooling: Deploys Encforge custom ransomware compiled in Go
- Modus operandi: AI-agent-driven operations, suggesting automated or semi-automated attack lifecycle
Affiliations
- Associated with Encforge ransomware deployment
- Possibly the same operator behind earlier Langflow attacks (per Sysdig research linking \xe2\x80\x9csecond attack\xe2\x80\x9d to same server)
Related Pages
- Encforge โ The Go ransomware deployed by JADEPUFFER
- Nadmesh Botnet โ Go-based botnet scanning for exposed AI services (potential overlap)