Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models

Blog post from Sysdig

Post Details
Company
Date Published
Author
Michael Clark
Word Count
4,114
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

In July 2026, the Sysdig Threat Research Team documented an advanced ransomware campaign by the threat actor JADEPUFFER, which specifically targets AI and machine learning infrastructure using a novel ransomware named ENCFORGE. Exploiting a vulnerability in the widely used Langflow framework, JADEPUFFER gained unauthorized access and deployed ransomware to destroy trained AI models, which are costly and time-consuming to recreate. The updated ransomware, built in Go and packed with UPX, targets a wide array of AI-related file extensions and employs sophisticated encryption techniques, including AES-256-CTR and RSA-2048, to render them inaccessible. Unlike typical ransomware, the focus here is on permanently disabling AI systems by encrypting model checkpoints, vector databases, and training datasets, which cannot simply be restored from backups. This evolution from improvised scripts to a professional toolkit highlights a significant shift in ransomware tactics, emphasizing the need for robust security measures in AI environments to prevent substantial financial and operational losses.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.