Researchers said the JADEPUFFER threat actor deployed a new ransomware strain, ENCFORGE (also reported as EncForge), against a previously compromised Langflow server by exploiting CVE-2025-3248, a critical unauthenticated remote code execution flaw affecting versions before 1.3.0. After gaining code execution, the attacker used an exposed Docker socket to escape the container, obtain root-level control on the host, and launch ransomware designed specifically for AI and machine learning environments. Sysdig linked the activity to earlier JADEPUFFER operations, including a second attack on the same vulnerable server and reuse of the Proton Mail address e78393397@proton.me.
ENCFORGE is described as a purpose-built ransomware family that targets roughly 180 file types tied to AI workflows, including model weights and checkpoints, vector databases and indexes, embeddings, and training datasets. The malware uses hybrid encryption based on AES-256 and RSA-2048, appends a .locked extension to encrypted files, drops ransom notes, and in one recovered sample deletes itself after execution; researchers also observed the operator iteratively generating multiple Python scripts within minutes when an initial payload failed, indicating real-time adaptation during the intrusion. Investigators found no evidence of data exfiltration, but warned that encrypting AI artifacts could force costly retraining and prolonged recovery, and urged organizations to patch Langflow, rotate exposed credentials, restrict Docker socket access, harden filesystem controls, and maintain offline or immutable backups of AI assets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Sysdig connected the ENCFORGE ransomware activity to the earlier JADEPUFFER operation, citing indicators including reuse of the Proton Mail address e78393397@proton.me. The attribution tied the new ransomware deployment to the same threat actor behind the prior Langflow compromise.
During the ransomware intrusion, the operator reportedly adjusted in real time after an initial payload delivery failure, generating six Python scripts in about five minutes before successfully executing encryption. This behavior was highlighted as evidence of autonomous or agentic adaptation during the attack.
In a second observed attack on the same vulnerable Langflow server, Sysdig linked JADEPUFFER to deployment of ENCFORGE, a custom ransomware designed to encrypt AI and machine learning assets including model files, vector indexes, and training datasets. Researchers found no evidence of data exfiltration in the recovered sample.
Sysdig reported that the JADEPUFFER operator compromised a Langflow instance vulnerable to CVE-2025-3248, a critical unauthenticated remote code execution flaw affecting versions before 1.3.0. The intrusion also leveraged an exposed Docker socket to escape the container and gain host-level control.
Sysdig published research detailing JADEPUFFER's exploitation of a vulnerable Langflow server, use of an exposed Docker socket for host escape, deployment of ENCFORGE ransomware targeting AI assets, and attribution of the activity to the same operator. The report highlighted the actor's rapid adaptation during payload delivery as evidence of agentic behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecuritymagazine.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcesysdig.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.