JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models
Blog post from Sysdig
In July 2026, the Sysdig Threat Research Team documented an advanced ransomware campaign by the threat actor JADEPUFFER, which specifically targets AI and machine learning infrastructure using a novel ransomware named ENCFORGE. Exploiting a vulnerability in the widely used Langflow framework, JADEPUFFER gained unauthorized access and deployed ransomware to destroy trained AI models, which are costly and time-consuming to recreate. The updated ransomware, built in Go and packed with UPX, targets a wide array of AI-related file extensions and employs sophisticated encryption techniques, including AES-256-CTR and RSA-2048, to render them inaccessible. Unlike typical ransomware, the focus here is on permanently disabling AI systems by encrypting model checkpoints, vector databases, and training datasets, which cannot simply be restored from backups. This evolution from improvised scripts to a professional toolkit highlights a significant shift in ransomware tactics, emphasizing the need for robust security measures in AI environments to prevent substantial financial and operational losses.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.