hacker-news · Crawled Jul 21, 2026
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
11 IoCs 3 CVEs
Read original article ↗
AI Summary
A new ransomware named ENCFORGE, attributed to the threat actor JADEPUFFER, is targeting AI model files through exploitation of a critical unauthenticated RCE vulnerability (CVE-2025-3248) in Langflow versions prior to 1.3.0. The attackers leverage the exposed Docker socket to escalate from container to host, deploying a custom-packed Go-based ransomware that encrypts AI-specific file types using AES-256-CTR and an embedded RSA-2048 public key. The ransomware avoids data exfiltration, instead relying solely on encryption, and leaves ransom notes with a Proton Mail contact reused from prior attacks, indicating campaign continuity.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 11 extracted
| Type | Value | Detail |
|---|---|---|
| IP | unknown | Details → |
| Domain | unknown | Details → |
| SHA-256 | 8cb0c223b018cecef1d990ec81c67b826eb3c30d54f06193cf69969e9a8baea2 | Details → |
| SHA-256 | ea7822eac6cecef7746c606b862b4d3034856caf754c4cf69533662637905328 | Details → |
| Filename | /.lockd | Details → |
| Filename | lockd | Details → |
| Filename | encfile | Details → |
| Filename | keyforge | Details → |
| Filename | HOW_TO_DECRYPT | Details → |
| Filename | README_DECRYPT | Details → |
| e78393397[@]proton[.]me | Details → |
MITRE ATT&CK TTPs 38 techniques
T1021 Remote Services · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1053.003 Cron · Execution T1055 Process Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.004 Unix Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.001 Clear Windows Event Logs · Defense Evasion T1071.001 Web Protocols · Command And Control T1075 T1075 T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1210 Exploitation of Remote Services · Lateral Movement T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1499 Endpoint Denial of Service · Impact T1505.003 Web Shell · Persistence T1552 Unsecured Credentials · Credential Access T1619 Cloud Storage Object Discovery · Discovery T1046 Network Service Discovery · Discovery T1090 Proxy · Command And Control T1203 Exploitation for Client Execution · Execution T1566 Phishing · Initial Access T1583 Acquire Infrastructure · Resource Development T1584 Compromise Infrastructure · Resource Development T1585 Establish Accounts · Resource Development T1586 Compromise Accounts · Resource Development T1587 Develop Capabilities · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development