Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Sysdig says that the attacker returned to the previously breached Langflow instance vulnerable to CVE-2025-3248 with the Go-based EncForge ransomware built specifically for AI and machine learning infrastructure. | The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
the final one (deploy.py v2) solving the delivery issues... launches the live encryption pass, and then counts .locked files to verify execution
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based ransomware payload built specifically for AI and machine learning infrastructure. It targets about 180 file extensions including model checkpoints, vector databases, training datasets, and embedding indexes, encrypts files using AES-256 with an RSA-2048-protected key, appends the .locked extension, and drops a ransom note.
A compiled Go ransomware family designed to encrypt AI/ML infrastructure assets, including model checkpoints, vector databases, training datasets, and embedding indices. It uses AES-256-CTR with RSA-2048 key wrapping, performs region-based encryption, appends .locked to files, drops ransom notes, kills processes holding file locks, supports idempotent resume, and self-deletes after execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.