An advanced threat actor identified as JADEPUFFER has evolved its capabilities, now deploying ENCFORGE, a specialized ransomware targeting AI and ML infrastructure. The actor exploits CVE-2025-3248 in Langflow to gain initial access, then autonomously chains reconnaissance, credential harvesting, and lateral movement. ENCFORGE is a compiled Go binary targeting approximately 180 file extensions specific to AI/ML environments, including model checkpoints, vector databases, training datasets, and embedding indices. The ransomware uses AES-256-CTR with RSA-2048 encryption and cannot be recovered without the attacker's private key. Unlike traditional ransomware, encrypted AI models cannot simply be restored, as rebuilding production-ready models costs between $75,000 to $500,000 per model in compute and engineering time. The operation demonstrates sophisticated autonomous behavior, including real-time container escape toolkit construction when initial payload delivery failed, completing the escape mechanism in ...
Created: 2026-07-21
Indicatorsは見つかっていない。
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。