bleeping-computer · Crawled Jul 20, 2026

JadePuffer agentic attacks now target AI model data with ransomware

2 IoCs 1 CVEs
Read original article ↗

AI Summary

The JadePuffer agentic threat actor has evolved to target AI/ML infrastructure using custom ransomware named EncForge, which encrypts critical AI assets such as model checkpoints, training datasets, and vector databases. The attack leverages autonomous decision-making to adapt in real time, deploying Python scripts to deliver the Go-based EncForge payload after gaining root access via an exposed Docker socket. The ransomware uses AES-256 and RSA-2048 encryption, appends '.locked' to encrypted files, and leaves a ransom note, though no data exfiltration was observed.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Filename deploy.py v2 Details →
Filename lockd Details →

MITRE ATT&CK TTPs 27 techniques