Close Menu
AIToday7

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How Much Does a Local LLM Actually Cost to Run? I Measured Every Watt on Apple Silicon

    July 28, 2026

    Discovering cryptographic weaknesses with Claude

    July 28, 2026

    Are you struggling to find a tech job on the West Coast?

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How Much Does a Local LLM Actually Cost to Run? I Measured Every Watt on Apple Silicon
    • Discovering cryptographic weaknesses with Claude
    • Are you struggling to find a tech job on the West Coast?
    • How AI Is Helping Teen Entrepreneurs Launch Startups
    • 12 keychain gadgets worth carrying every day (and why they’re worth it)
    • More than 30 Minnesota water systems targeted in cyberattack
    • Alaina Lamberson, Recognized by Influential Women, Serves as API Integration Specialist and Prompt Engineer at Portable
    • Elon Musk’s xAI sues to stop Minnesota law banning nudification technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AIToday7
    • Home
    • AI News
    • Tech News
    • AI Guides
    • Chatbots
    • Cybersecurity
    • Gadgets
    • More
      • Generative AI
      • Startups
    AIToday7
    Home»Cybersecurity»JadePuffer Returns With Ransomware Designed to Wipe AI Models
    Cybersecurity

    JadePuffer Returns With Ransomware Designed to Wipe AI Models

    aitoday7By aitoday7July 20, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    JadePuffer Returns With Ransomware Designed to Wipe AI Models
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The agentic operatordocumented as the first ransomware campaign run end-to-end by a large language model (LLM) has returned with a purpose-built locker designed to destroy trained AI model artifacts.

    According tonew research from the Sysdig Threat Research Team (TRT) published one July 20, JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary that targets roughly 180 file extensions across the modern machine learning stack.

    The payload’s targeting is deliberate rather than opportunistic. Named formats include PyTorch and TensorFlow checkpoints, HuggingFace SafeTensors weights, llama.cpp GGUF quantized models, FAISS vector indices, Apache Parquet and TFRecord training datasets and NumPy arrays.

    Read more on AI-framework exploitation: Hackers Exploit Critical Langflow Bug in Just 20 Hours

    Rebuilding Costs Where Backups Do Not Help

    Backups can restore encrypted business data, but for production model, the gap between the last clean snapshot and the attack often represents weeks or months of training runs, fine-tuning iterations and data curation.

    Sysdig said reproducing that gap requires re-running training at $75,000 to $500,000 per model in cloud GPU and engineering time. If the training data is on the same host, recovery is blocked entirely until that data is reconstructed.

    The observed ENCFORGE binary swept every model variant on shared storage in one pass. A command-line interface –include flag let operators append custom extensions per campaign, and the binary’s own help text named LoRA fine-tune adapters and legacy GGML weights as the example.

    Sysdig attributed the operation to JadePuffer on the strength of the extortion contact embedded in the binary, which matches the address disclosed in its earlier report.

    Container Escape Built in Real Time

    Entry was again through CVE-2025-3248, a missing-authentication flaw in Langflow’s code validation endpoint that CISA added to its Known Exploited Vulnerabilities catalog in May 2025.

    Once inside, the agent ran through the familiar reconnaissance and credential-harvest routine seen in the first campaign, then discovered a mounted Docker socket and moved to fetch the ransomware payload.

    When the binary fetch from JadePuffer’s command-and-control (C2) server failed inside the container, the operator rebuilt the delivery mechanism on the fly.

    Over five minutes and 24 seconds, it iterated six Python scripts through the Langflow RCE channel, converging on a working pipeline that used the mounted Docker socket to spawn a privileged escape container, copied the locker across the namespace boundaryfilesystem outside the original container’s isolation

    ENCFORGE itself uses AES-256-CTR with an RSA-2048 key exchange, kills processes holding file locks before encrypting and self-deletes after running.

    Sysdig found no data-exfiltration capability in the binary and no leak site, which places JadePuffer outside the double-extortion model used by most ransomware-as-a-service (RaaS) groups. The threat is the destruction itself, not disclosure.

    Designed JadePuffer ransomware Returns Wipe
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNooklab Unveils Vision for a Low Distraction AI Screen
    Next Article 5 Smartphones With The Best Resale Value In 2026
    aitoday7
    • Website

    Related Posts

    Cybersecurity

    More than 30 Minnesota water systems targeted in cyberattack

    July 28, 2026
    Cybersecurity

    Sextortion scammers are exploiting ShinyHunters data leaks

    July 28, 2026
    Cybersecurity

    Rethinking security for the age of AI

    July 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    How Much Does a Local LLM Actually Cost to Run? I Measured Every Watt on Apple Silicon

    July 28, 20260 Views

    Discovering cryptographic weaknesses with Claude

    July 28, 20260 Views

    Are you struggling to find a tech job on the West Coast?

    July 28, 20260 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Chatbots

    OpenAI bets on families as ChatGPT goes deeper into households

    aitoday7July 11, 2026
    Generative AI

    MUSIC COMMUNITY INTRODUCES NEW LABELING PROGRAM TO DISTINGUISH GENERATIVE AI IN SOUND RECORDINGS

    aitoday7July 11, 2026
    AI News

    Safe from AI: which jobs will help you thrive in the future?

    aitoday7July 11, 2026

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    How Much Does a Local LLM Actually Cost to Run? I Measured Every Watt on Apple Silicon

    July 28, 20260 Views

    Discovering cryptographic weaknesses with Claude

    July 28, 20260 Views

    Are you struggling to find a tech job on the West Coast?

    July 28, 20260 Views
    Our Picks

    OpenAI bets on families as ChatGPT goes deeper into households

    July 11, 2026

    MUSIC COMMUNITY INTRODUCES NEW LABELING PROGRAM TO DISTINGUISH GENERATIVE AI IN SOUND RECORDINGS

    July 11, 2026

    Safe from AI: which jobs will help you thrive in the future?

    July 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 AIToday7. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.