Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Cruciferra Crypter Uses Process Ghosting to Evade Detection

July 20, 2026

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

July 20, 2026

Researchers Build WordPress Exploit Using OpenAI’s GPT

July 20, 2026
Facebook X (Twitter) Instagram
Monday, July 20
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»JadePuffer Returns With Ransomware Designed to Wipe AI Models
News

JadePuffer Returns With Ransomware Designed to Wipe AI Models

Team-CWDBy Team-CWDJuly 20, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The agentic operator documented as the first ransomware campaign run end-to-end by a large language model (LLM) has returned with a purpose-built locker designed to destroy trained AI model artifacts.

According to new research from the Sysdig Threat Research Team (TRT) published one July 20, JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary that targets roughly 180 file extensions across the modern machine learning stack.

The payload’s targeting is deliberate rather than opportunistic. Named formats include PyTorch and TensorFlow checkpoints, HuggingFace SafeTensors weights, llama.cpp GGUF quantized models, FAISS vector indices, Apache Parquet and TFRecord training datasets and NumPy arrays.

Read more on AI-framework exploitation: Hackers Exploit Critical Langflow Bug in Just 20 Hours

Rebuilding Costs Where Backups Do Not Help

Backups can restore encrypted business data, but for production model, the gap between the last clean snapshot and the attack often represents weeks or months of training runs, fine-tuning iterations and data curation.

Sysdig said reproducing that gap requires re-running training at $75,000 to $500,000 per model in cloud GPU and engineering time. If the training data is on the same host, recovery is blocked entirely until that data is reconstructed.

The observed ENCFORGE binary swept every model variant on shared storage in one pass. A command-line interface –include flag let operators append custom extensions per campaign, and the binary’s own help text named LoRA fine-tune adapters and legacy GGML weights as the example.

Sysdig attributed the operation to JadePuffer on the strength of the extortion contact embedded in the binary, which matches the address disclosed in its earlier report.

Container Escape Built in Real Time

Entry was again through CVE-2025-3248, a missing-authentication flaw in Langflow’s code validation endpoint that CISA added to its Known Exploited Vulnerabilities catalog in May 2025.

Once inside, the agent ran through the familiar reconnaissance and credential-harvest routine seen in the first campaign, then discovered a mounted Docker socket and moved to fetch the ransomware payload.

When the binary fetch from JadePuffer’s command-and-control (C2) server failed inside the container, the operator rebuilt the delivery mechanism on the fly.

Over five minutes and 24 seconds, it iterated six Python scripts through the Langflow RCE channel, converging on a working pipeline that used the mounted Docker socket to spawn a privileged escape container, copied the locker across the namespace boundary via the host’s procfs, then ran the encryption pass on the host filesystem outside the original container’s isolation.

ENCFORGE itself uses AES-256-CTR with an RSA-2048 key exchange, kills processes holding file locks before encrypting and self-deletes after running.

Sysdig found no data-exfiltration capability in the binary and no leak site, which places JadePuffer outside the double-extortion model used by most ransomware-as-a-service (RaaS) groups. The threat is the destruction itself, not disclosure.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleLabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Next Article Researchers Build WordPress Exploit Using OpenAI’s GPT
Team-CWD
  • Website

Related Posts

News

Cruciferra Crypter Uses Process Ghosting to Evade Detection

July 20, 2026
News

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

July 20, 2026
News

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

July 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

A phishing attack that doesn’t steal your password

June 15, 2026

What it takes to fool facial recognition

March 14, 2026

It’s all fun and games until someone gets hacked

September 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.