Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-21 ยท updated: 2026-07-21 ยท tags: [cybercrime-group, ransomware-group] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: false

JADEPUFFER โ€” AI-Agent-Driven Threat Actor

JADEPUFFER is an AI-agent-driven cybercrime operator that targets AI infrastructure, particularly Langflow servers. The operator has been linked to multiple attacks on the same Langflow deployment, with Sysdig researchers confirming a second attack via the same entry vector.

TTPs

  • Entry point: CVE-2025-3248 (CVSS 9.8) โ€” critical Langflow vulnerability, in CISA's KEV catalog since May 2025
  • Target: AI infrastructure โ€” model weights, vector indexes, training datasets
  • Tooling: Deploys Encforge custom ransomware compiled in Go
  • Modus operandi: AI-agent-driven operations, suggesting automated or semi-automated attack lifecycle

Affiliations

  • Associated with Encforge ransomware deployment
  • Possibly the same operator behind earlier Langflow attacks (per Sysdig research linking \xe2\x80\x9csecond attack\xe2\x80\x9d to same server)

Related Pages

  • Encforge โ€” The Go ransomware deployed by JADEPUFFER
  • Nadmesh Botnet โ€” Go-based botnet scanning for exposed AI services (potential overlap)