INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Langflow RCE Attack Targets AI Model Files
| 2026-07-21 07:34 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The Langflow ransomware campaign has escalated to a new level of sophistication, with the deployment of an updated version of ENCFORGE, a previously unknown and highly targeted ransomware designed to encrypt AI model files. The attackers have also demonstrated their ability to exploit vulnerabilities in popular software, including Docker and Nacos, making them more difficult to detect and mitigate. As a result, organizations must take immediate action to upgrade Langflow to the latest supported version and ensure that all containers are properly secured against future attacks.
Technical Mitigations AI-generated
* Use secure coding practices, such as input validation and error handling, to prevent exploitation of vulnerabilities like CVE-2025-3248.
* Implement a least privilege access model for AI agents and models, limiting their access to sensitive data and infrastructure.
* Regularly update and patch dependencies, including libraries and frameworks used by AI models, to ensure that known vulnerabilities are addressed.
* Monitor and detect suspicious activity related to AI assets, such as encryption or deletion of files, to identify potential threats early on.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
de•••••.py
ll•••••.cpp
do•••••.sock
e7•••@pr•••.•••
8cb0c2••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ea7822••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BlackCatBlackCat
CVE-2025-3248CVE-2025-3248
CVE-2026-33017CVE-2026-33017
CVE-2026-55255CVE-2026-55255
Target & Sectors
Global Scope
Incident Timeline
May 5, 2025
Threat actors used a known exploited vulnerability in the JadePuffer AI Model to target systems.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-3248
The flaw,
CVE-2025-3248
, carries a CVSS score of 9.8 and has been in CISA's Known Exploited Vulnerabilities
catalog
since May 5, 2025.
vulnerability
CVSS score of 9.8
The flaw,
CVE-2025-3248
, carries a CVSS score of 9.8 and has been in CISA's Known Exploited Vulnerabilities
catalog
since May 5, 2025.
attribution
CVE-2025
The flaw,
CVE-2025-3248
, carries a CVSS score of 9.8 and has been in CISA's Known Exploited Vulnerabilities
catalog
since May 5, 2025.
attribution
CVSS
The flaw,
CVE-2025-3248
, carries a CVSS score of 9.8 and has been in CISA's Known Exploited Vulnerabilities
catalog
since May 5, 2025.
tactic
T1588.006 - Vulnerabilities
The flaw,
CVE-2025-3248
, carries a CVSS score of 9.8 and has been in CISA's Known Exploited Vulnerabilities
catalog
since May 5, 2025.
May 2025
Threat actors used CVE-2025-3248 to target a Container Escape Built in Real Time using the JadePuffer AI Model Ransomware Attacks.
Click on any entity below to view its context and source!
attribution
CVE-2025-3248
Container Escape Built in Real Time
Entry was again through CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint that CISA added to its Known Exploited Vulnerabilities catalog in May 2025.
tactic
T1588.006 - Vulnerabilities
Container Escape Built in Real Time
Entry was again through CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint that CISA added to its Known Exploited Vulnerabilities catalog in May 2025.
attribution
Container Escape Built in Real Time
Entry
Container Escape Built in Real Time
Entry was again through CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint that CISA added to its Known Exploited Vulnerabilities catalog in May 2025.
attribution
CISA
Container Escape Built in Real Time
Entry was again through CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint that CISA added to its Known Exploited Vulnerabilities catalog in May 2025.
attribution
Known Exploited
Container Escape Built in Real Time
Entry was again through CVE-2025-3248, a missing-authentication flaw in Langflow's code validation endpoint that CISA added to its Known Exploited Vulnerabilities catalog in May 2025.
March 25, 2026
Threat actors used stolen data from a prominent AI model to launch JadePuffer ransomware attacks on multiple organizations.
July 7, 2026
Threat actors used a previously unknown Langflow vulnerability in the JadePuffer AI Model Ransomware Attack.
Click on any entity below to view its context and source!
infrastructure
1.3.0
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
vulnerability
CVE-2025-3248
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
attribution
CVE-2025
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
infrastructure
1.9.1
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
vulnerability
CVE-2026-33017
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
vulnerability
CVE-2026-55255
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
infrastructure
1.9.0
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
attribution
KEV
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
attribution
RCE
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
attribution
KEV March 25, 2026
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
general_metric
25 KEV March
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
general_metric
2026 KEV March
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
2026/07/20
Ransomware attackers used CVE-2025-3248 to target the previously breached Langflow instance.
Click on any entity below to view its context and source!
tactic
Ransomware
Latest attack
In a report today, Sysdig says that the attacker returned to the previously breached Langflow instance vulnerable to CVE-2025-3248 with the Go-based EncForge ransomware "built specifically for AI and machine learning (ML) infrastructure.
organisation
CVE-2025-3248
Latest attack
In a report today, Sysdig says that the attacker returned to the previously breached Langflow instance vulnerable to CVE-2025-3248 with the Go-based EncForge ransomware "built specifically for AI and machine learning (ML) infrastructure.
organisation
Sysdig
Latest attack
In a report today, Sysdig says that the attacker returned to the previously breached Langflow instance vulnerable to CVE-2025-3248 with the Go-based EncForge ransomware "built specifically for AI and machine learning (ML) infrastructure.
organisation
ML
Latest attack
In a report today, Sysdig says that the attacker returned to the previously breached Langflow instance vulnerable to CVE-2025-3248 with the Go-based EncForge ransomware "built specifically for AI and machine learning (ML) infrastructure.
July 20
JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary targeting roughly 180 file extensions.
Click on any entity below to view its context and source!
tactic
Ransomware
According to
new research
from the Sysdig Threat Research Team (TRT) published one July 20, JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary that targets roughly 180 file extensions across the modern machine learning stack.
organisation
UPX
According to
new research
from the Sysdig Threat Research Team (TRT) published one July 20, JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary that targets roughly 180 file extensions across the modern machine learning stack.
data_breach
180 file extensions
According to
new research
from the Sysdig Threat Research Team (TRT) published one July 20, JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary that targets roughly 180 file extensions across the modern machine learning stack.
organisation
the Sysdig Threat Research Team
According to
new research
from the Sysdig Threat Research Team (TRT) published one July 20, JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary that targets roughly 180 file extensions across the modern machine learning stack.
organisation
TRT
According to
new research
from the Sysdig Threat Research Team (TRT) published one July 20, JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary that targets roughly 180 file extensions across the modern machine learning stack.
2026/07/21
JadePuffer, an agentic threat actor capable of running autonomously through the stages of a ransomware attack from initial access to data encryption.
Click on any entity below to view its context and source!
organisation
UPX
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF and GGML weights
FAISS vector indexes
Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats
Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor.
The file is a UPX 5.20-packed static Go 1.22.12 ELF.
organisation
PyTorch
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF and GGML weights
FAISS vector indexes
Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats
Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor.
Its default extension list covers PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors, ONNX interchange format, GGUF (the current standard for locally deployed LLMs) and its predecessor GGML, FAISS vector indexes, Parquet and Arrow training datasets, NumPy arrays, and TensorFlow records.
Named formats include PyTorch and TensorFlow checkpoints, HuggingFace SafeTensors weights, llama.cpp GGUF quantized models, FAISS vector indices, Apache Parquet and TFRecord training datasets and NumPy arrays.
organisation
TensorFlow
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF and GGML weights
FAISS vector indexes
Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats
Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor.
Its default extension list covers PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors, ONNX interchange format, GGUF (the current standard for locally deployed LLMs) and its predecessor GGML, FAISS vector indexes, Parquet and Arrow training datasets, NumPy arrays, and TensorFlow records.
Named formats include PyTorch and TensorFlow checkpoints, HuggingFace SafeTensors weights, llama.cpp GGUF quantized models, FAISS vector indices, Apache Parquet and TFRecord training datasets and NumPy arrays.
organisation
Hugging Face SafeTensors
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF and GGML weights
FAISS vector indexes
Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats
Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor.
Its default extension list covers PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors, ONNX interchange format, GGUF (the current standard for locally deployed LLMs) and its predecessor GGML, FAISS vector indexes, Parquet and Arrow training datasets, NumPy arrays, and TensorFlow records.
organisation
GGUF
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF and GGML weights
FAISS vector indexes
Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats
Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor.
Its default extension list covers PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors, ONNX interchange format, GGUF (the current standard for locally deployed LLMs) and its predecessor GGML, FAISS vector indexes, Parquet and Arrow training datasets, NumPy arrays, and TensorFlow records.
Named formats include PyTorch and TensorFlow checkpoints, HuggingFace SafeTensors weights, llama.cpp GGUF quantized models, FAISS vector indices, Apache Parquet and TFRecord training datasets and NumPy arrays.
organisation
GGML
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF and GGML weights
FAISS vector indexes
Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats
Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor.
Its default extension list covers PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors, ONNX interchange format, GGUF (the current standard for locally deployed LLMs) and its predecessor GGML, FAISS vector indexes, Parquet and Arrow training datasets, NumPy arrays, and TensorFlow records.
organisation
LoRA
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF and GGML weights
FAISS vector indexes
Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats
Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor.
Those examples point directly at AI environments; a generic file locker would have little reason to name LoRA adapters or legacy GGML weights.
A command-line interface --include flag let operators append custom extensions per campaign, and the binary's own help text named LoRA fine-tune adapters and legacy GGML weights as the example.
organisation
EncForce
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF and GGML weights
FAISS vector indexes
Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats
Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor.
data_breach
180 file extensions
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF and GGML weights
FAISS vector indexes
Training datasets, including Parquet, Arrow, TFRecord, NumPy, and DuckDB formats
Its command-line help also uses LoRA adapters and legacy GGML files as examples of additional targets, which Sysdig sees as evidence that the ransomware was deliberately built for AI environments rather than a generic file encryptor.
"
"The binary targets approximately 180 file extensions, with a deliberately broad sweep of the modern AI/ML stack, including model checkpoints, vector databases, training datasets, and embedding indices in nearly every current format," Sysdig says.
organisation
LLM
The agentic operator
documented
as the first ransomware campaign run end-to-end by a large language model (LLM) has returned with a purpose-built locker designed to destroy trained AI model artifacts.
organisation
Tor
It carries no networking code, cloud storage client, or staging mechanism, and researchers found no evidence of data exfiltration, a leak site, or a Tor payment portal during the session it observed.
organisation
JADEPUFFER
Sysdig attributed the operation to JadePuffer on the strength of the extortion contact embedded in the binary, which matches the address disclosed in its earlier report.
From Langflow to the Host
After confirming code execution, JADEPUFFER swept the container for credentials and found the Docker socket at
/var/run/docker.sock
.
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
infrastructure
1.3.0
Langflow versions before 1.3.0
expose the
/api/v1/validate/code
endpoint without authentication, allowing any remote attacker to execute arbitrary Python on the server.
Defense suggestions include applying available security updates, most notably Langflow version 1.3.0 or later, restricting Docket socket access, running Langflow containers as non-root, and applying filesystem-level access controls to model weight directories.
organisation
Docket
Defense suggestions include applying available security updates, most notably Langflow version 1.3.0 or later, restricting Docket socket access, running Langflow containers as non-root, and applying filesystem-level access controls to model weight directories.
organisation
The Hacker News
As The Hacker News reported earlier this month, the prior operation used throwaway Python code and MySQL's
AES_ENCRYPT()
function to encrypt and destroy data in Nacos (Alibaba's configuration server) and production databases.
organisation
Langflow RCE
Over five minutes and 24 seconds, it iterated six Python scripts through the Langflow RCE channel, converging on a working pipeline that used the mounted Docker socket to spawn a privileged escape container, copied the locker across the namespace boundary via the host's procfs, then ran the encryption pass on the host filesystem outside the original container's isolation.
organisation
Docker
From Langflow to the Host
After confirming code execution, JADEPUFFER swept the container for credentials and found the Docker socket at
/var/run/docker.sock
.
organisation
ENCFORGE
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
ENCFORGE uses AES-256-CTR for file data, with the per-run symmetric key wrapped under an embedded RSA-2048 public key compiled into this build.
ENCFORGE itself uses AES-256-CTR with an RSA-2048 key exchange, kills processes holding file locks before encrypting and self-deletes after running.
infrastructure
1.9.1
Upgrade Langflow to 1.9.1 or a current supported release.
organisation
The ENCFORGE Payload
Researchers
The ENCFORGE Payload
Researchers retrieved the binary from the attacker's command-and-control server, where it was hidden as
/.lockd
; a direct request to
/lockd
returns 404, and the leading dot keeps it off a plain directory listing.
organisation
NumPy
Its default extension list covers PyTorch and TensorFlow checkpoints, Hugging Face SafeTensors, ONNX interchange format, GGUF (the current standard for locally deployed LLMs) and its predecessor GGML, FAISS vector indexes, Parquet and Arrow training datasets, NumPy arrays, and TensorFlow records.
organisation
HuggingFace SafeTensors
Named formats include PyTorch and TensorFlow checkpoints, HuggingFace SafeTensors weights, llama.cpp GGUF quantized models, FAISS vector indices, Apache Parquet and TFRecord training datasets and NumPy arrays.
organisation
TFRecord
Named formats include PyTorch and TensorFlow checkpoints, HuggingFace SafeTensors weights, llama.cpp GGUF quantized models, FAISS vector indices, Apache Parquet and TFRecord training datasets and NumPy arrays.
organisation
AES-256-CTR
ENCFORGE uses AES-256-CTR for file data, with the per-run symmetric key wrapped under an embedded RSA-2048 public key compiled into this build.
ENCFORGE itself uses AES-256-CTR with an RSA-2048 key exchange, kills processes holding file locks before encrypting and self-deletes after running.
organisation
LockBit
Rather than encrypting whole files, it encrypts selected regions, the same speed optimization LockBit and BlackCat-class lockers use.
organisation
GCP
Its first attempt to pull ENCFORGE from the GCP command-and-control server failed.
organisation
PID
The final version used the Docker API to spin up a privileged container with the host PID namespace and root filesystem mounted, located the target process, copied ENCFORGE through
/proc/<pid>/root
, then ran it on the host via
nsenter
.
“deploy.py v2 is the completed payload: a fully autonomous pipeline that discovers the target PID, copies ENCFORGE across the namespace boundary via procfs, runs a try-mode scan, launches the live encryption pass, and then counts .locked files to verify execution,”
Sysdig explained
.
organisation
GPU
Patch Langflow, Then Protect the Models
Researchers estimate that rebuilding a production AI model once it has been encrypted could cost between $75,000 and $500,000 per model in cloud GPU compute and engineering time.
financial
$75,000 model
Patch Langflow, Then Protect the Models
Researchers estimate that rebuilding a production AI model once it has been encrypted could cost between $75,000 and $500,000 per model in cloud GPU compute and engineering time.
organisation
YARA
Sysdig has published the source and C2 addresses, the embedded RSA-2048 key fingerprint, and a YARA rule in its full report.
organisation
Rotate
Rotate AI provider keys, cloud credentials, database secrets, and any other tokens accessible to the Langflow process.
organisation
Keep
Keep model weights, vector indexes, and training datasets in offline or immutable snapshots.
organisation
Threat Research Team
The Hacker News contacted Sysdig's Threat Research Team for further detail on the fleet campaign scope and attribution confidence; Sysdig had not responded by publication.
organisation
Sysdig
Sysdig said reproducing that gap requires re-running training at $75,000 to $500,000 per model in cloud GPU and engineering time.
organisation
AI/ML
"
"The binary targets approximately 180 file extensions, with a deliberately broad sweep of the modern AI/ML stack, including model checkpoints, vector databases, training datasets, and embedding indices in nearly every current format," Sysdig says.
infrastructure
Linux
Analysis of the Linux variant revealed the presence of Windows anti-recovery functions such as shadow copy deletion and boot recovery disabling.
infrastructure
Windows
Analysis of the Linux variant revealed the presence of Windows anti-recovery functions such as shadow copy deletion and boot recovery disabling.
infrastructure
Macos
A macOS version, although hinted in the code, remains unconfirmed.
organisation
API
After gaining access and searching for cloud credentials, API tokens, and reachable internal services, the threat actor discovered an exposed Docker socket that provided root-level control.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Tactical Metrics
Metrics
infrastructure
1.3.0
Software Version
Click for context!
Langflow versions before 1.3.0
expose the
/api/v1/validate/code
endpoint without authentication, allowing any remote attacker to execute arbitrary Python on the server.
Version 1.3.0 closed
CVE-2025-3248
, the entry vector for this campaign, but CISA has since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and…
Defense suggestions include applying available security updates, most notably Langflow version 1.3.0 or later, restricting Docket socket access, running Langflow containers as non-root, and applying filesystem-level access controls to model weight…
Metrics
infrastructure
1.9.1
Software Version
Upgrade Langflow to 1.9.1 or a current supported release.
…since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 2026.
Metrics
infrastructure
1.9.0
Software Version
…as since added two more Langflow vulnerabilities to its KEV catalog:
CVE-2026-33017
, an unauthenticated RCE flaw fixed in 1.9.0, added to KEV March 25, 2026; and
CVE-2026-55255
, a cross-user authorization bypass fixed in 1.9.1, added July 7, 20…
Metrics
financial
75,000
Model
Patch Langflow, Then Protect the Models
Researchers estimate that rebuilding a production AI model once it has been encrypted could cost between $75,000 and $500,000 per model in cloud GPU compute and engineering time.
Metrics
data_breach
180
File Extensions
EncForce ransomware
The Go-based binary (lockd) is packed using the Ultimate Packer for eXecutables (UPX) that targets 180 file extensions, including:
AI model checkpoints
Hugging Face SafeTensors files
PyTorch and TensorFlow models
GGUF…
"
"The binary targets approximately 180 file extensions, with a deliberately broad sweep of the modern AI/ML stack, including model checkpoints, vector databases, training datasets, and embedding indices in nearly every current format," Sysdig sa…
…m (TRT) published one July 20, JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary that targets roughly 180 file extensions across the modern machine learning stack.
Metrics
infrastructure
Linux
Affected Product
Analysis of the Linux variant revealed the presence of Windows anti-recovery functions such as shadow copy deletion and boot recovery disabling.
Metrics
infrastructure
Windows
Affected Product
Analysis of the Linux variant revealed the presence of Windows anti-recovery functions such as shadow copy deletion and boot recovery disabling.
Metrics
infrastructure
Macos
Affected Product
A macOS version, although hinted in the code, remains unconfirmed.
Intelligence Sources
The Hacker News
2026-07-21
Infosecurity-Magazine
2026-07-20
JadePuffer Returns With Ransomware Designed to Wipe AI Models
Infosecurity-Magazine
BleepingComputer
2026-07-20
JadePuffer agentic attacks now target AI model data with ransomware
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-21T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
37x
organisation
Identified Entity
Tor
entity
9x
attribution
Attributing Entity
CVE-2025
authority
7x
timeline
Temporal Reference
May 5, 2025
date
4x
tactic
Cyber Operation Type
Ransomware
tactic
3x
infrastructure
Software Version
1.3.0
version
3x
vulnerability
Exploited CVE
CVE-2025-3248
cve
3x
infrastructure
Affected Product
Linux
software
2x
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
2x
general metric
Kev March
25
kev march
2x
general metric
Seconds
24
seconds
2x
general metric
%
54
%
Contextual Telemetry
Context Block
8 METRICS
vulnerability
CVSS Score
10
score
general metric
/Lockd
404
/lockd
general metric
Upx
5
upx
malware
Malware Payload
BlackCat
tool
financial
Model
75,000
model
general metric
Extensions
180
extensions
industry
Targeted Sector
Defense
sector
data breach
File Extensions
180
file extensions
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.