ENCFORGE is a Go-based ransomware family designed to encrypt artificial intelligence and machine-learning assets. Associated with the JADEPUFFER threat actor, it has been deployed against Linux infrastructure following exploitation of CVE-2025-3248, an unauthenticated remote-code-execution vulnerability in Langflow. In the observed deployment chain, the operator abused an exposed Docker socket to create a privileged container, cross the container-host boundary, and execute the ransomware on the host.
The ransomware targets approximately 180 file extensions covering model checkpoints, model weights, vector indexes, embedding data, training datasets, and other machine-learning artifacts. Its targets include PyTorch and TensorFlow models, SafeTensors, ONNX, GGUF and GGML weights, FAISS indexes, and datasets in Parquet, Arrow, TFRecord, and NumPy formats. A command-line interface allows operators to extend the default targeting list and perform a trial scan before encryption; a companion key-generation tool is also referenced.
ENCFORGE uses region-based encryption with AES-256-CTR and wraps the per-run symmetric key with an embedded RSA-2048 public key. It renames encrypted files, drops ransom notes, terminates processes holding targeted files open, and supports resuming interrupted execution without re-encrypting completed files. The observed binary is packed with UPX and can delete itself after execution.
The operation focuses on encryption-based extortion and disruption of AI infrastructure. No data-exfiltration mechanism was identified in the recovered binary, and no data theft or associated leak site was observed in the documented campaign. Attribution to JADEPUFFER was supported by reuse of the extortion contact from the actor's earlier activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
JADEPUFFER's earlier agentic ransomware attack exploited the known Langflow vulnerability CVE-2025-3248 to gain access, collect credentials, move laterally, encrypt Nacos-service configuration files, delete original database tables, and leave a Bitcoin ransom note.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The same Langflow instance was subsequently targeted by the threat actor a second time using a compiled Go-based ransomware strain codenamed ENCFORGE.
The same Langflow instance was subsequently targeted by the threat actor a second time using a compiled Go-based ransomware strain codenamed ENCFORGE.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
the AI agent exploited the same Langflow vulnerability that was used in the earlier attack and located an exposed Docker socket that it leveraged to create a privileged escape container and deploy the ENCFORGE payload.
“[It] replayed the credentials against internal databases and cache services to see what they would unlock.”
Following encrypting the targeted files, ENCFORGE terminated processes holding file locks and deleted itself once the encryption was complete.
“[It] replayed the credentials against internal databases and cache services to see what they would unlock.”
By launching a privileged container over the mounted Docker socket, the ransomware was moved across the container boundary through the host's proc file system and executed against the host file system outside the original container's isolation using the mounted Docker socket.
An ENCFORGE binary was deployed in the second campaign that searched for 180 different file extensions... ENCFORGE is specifically designed to identify AI-related assets.
The attacker generated multiple Python scripts using the compromised Langflow environment... the scripts were able to develop a method for exiting the container environment through the exposed Docker socket and executing the ransomware on the host machine.
Unlike conventional ransomware targets, however, encrypted AI model artifacts cannot be restored after they are wiped.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based ransomware variant tailored to AI infrastructure. It scans a broad range of AI-related files and macOS-specific files for encryption.
A compiled Go-based ransomware strain designed to target AI infrastructure. It scans for nearly 180 file extensions associated with model checkpoints, vector databases, training datasets, embedding indices, and macOS-focused files.
A purpose-built ransomware binary targeting AI and machine-learning artifacts, including model formats, vector indexes, training datasets, LoRA fine-tune adapters, and model weights. It uses region-based hybrid encryption: AES-256-CTR per-run keys wrapped with an embedded RSA-2048 public key, and renames encrypted files with a .locked extension.
Purpose-built ransomware that encrypts AI/ML assets. It uses hybrid AES-256-CTR and embedded RSA-2048 encryption, encrypts regions of files, and renames encrypted files with a .locked extension. It was deployed by JADEPUFFER to destroy and extort organizations' model checkpoints, datasets, vector stores, and related ML artifacts without data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.