Critical Langflow Flaw Lets JADEPUFFER Deploy ENCFORGE AI Ransomware
Key Takeaways The JADEPUFFER threat actor is now deploying ENCFORGE, a new ransomware strain specifically designed to target AI models, training data, and vector databases. The attack chain begins by...
Key Takeaways
- The JADEPUFFER threat actor is now deploying ENCFORGE, a new ransomware strain specifically designed to target AI models, training data, and vector databases.
- The attack chain begins by exploiting CVE-2025-3248, a critical authentication bypass vulnerability in Langflow’s code-validation endpoint, allowing unauthenticated remote code execution.
- Organizations running vulnerable Langflow instances (versions prior to 1.3.0) are at high risk.
- ENCFORGE employs AES-256-CTR and RSA-2048 encryption, adding a ‘.locked’ extension to compromised files. Unlike many ransomware variants, it does not appear to involve data exfiltration.
- A patch is available, and immediate remediation is crucial, especially for systems exposed to the internet.
A new ransomware campaign is underway, marking a significant evolution in cyber threats as it specifically targets the critical infrastructure underpinning artificial intelligence systems. The threat actor, identified as JADEPUFFER, has escalated its capabilities from merely disrupting databases to deploying an advanced ransomware variant dubbed ENCFORGE. This sophisticated malware is engineered to encrypt AI models, their associated training data, and vital vector databases, according to a recent analysis.
Table Of Content
Exploiting Langflow for Initial Access
The campaign initiates its attack by leveraging CVE-2025-3248, a critical authentication bypass vulnerability present in the code-validation endpoint of Langflow. This flaw grants an unauthenticated attacker the ability to execute arbitrary Python code on exposed servers. Such a compromise creates an immediate gateway into environments that frequently house sensitive assets, including cloud keys, API tokens, and critical database credentials. Prior reporting has detailed how this critical Langflow vulnerability enables code injection.
Researchers at Sysdig first identified this heightened activity after observing JADEPUFFER returning to a previously compromised Langflow instance. This time, the threat actor arrived equipped with a significantly more advanced and autonomous toolkit. Sysdig said in a report shared with Cyber Security News (CSN) that JADEPUFFER conducted reconnaissance, harvested credentials, probed internal services, and meticulously prepared a route for privilege escalation from a containerized environment to the underlying host system.
The ramifications of such an attack extend far beyond typical data loss. The encryption of a production AI model can signify the loss of months of intensive training, fine-tuning, data preparation, and specialized engineering work. Even with robust backup strategies, organizations face potential setbacks from losing recent progress, while the effort to reconstruct proprietary training datasets could significantly prolong recovery times.
Agentic JADEPUFFER Exploits Langflow Flaw
Upon establishing initial access, JADEPUFFER immediately began a systematic search for credentials and scrutinized the Docker socket. Access to the Docker socket is particularly dangerous as it can grant a process the ability to create highly privileged containers, effectively allowing an attacker to escape the confines of the initial compromised container.
Initially, the actor attempted to directly download the ENCFORGE payload. When this file transfer failed, JADEPUFFER demonstrated remarkable adaptability. The attacker rapidly developed custom scripts to bypass the failure, successfully copying the payload through the container’s process filesystem and launching it directly on the host machine. This method involved the use of privileged containers, host process access, and host filesystem mounts to achieve the crucial container escape.
This sophisticated maneuver highlights a persistent risk associated with inadequately secured container environments. It mirrors scenarios where <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/bf5af289-5e1b-407a-9037-ae559a89f0c8/Agentic-JADEPUFFER-Exploits-Langflow-Flaw-to-Deploy-ENCFORGE-AI-Ransomware.pdf?AWSAccessKeyId=ASIA2F3EMEYEZCJPJF7Y&Signature=hQaX1DngRd3b92Sd7xaYszQItao%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEPP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBwCijVfwKOPIrZldiwysmE6wHJmd%2F60QQ77GwtB2RVTAiEAho0R%2BU09JpHSfeMvXXApbaaAbjrChJ5QvkD5WUHIRDwq%2FAQIvP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDBe%2BUXqPCNmOGs273CrQBC1ohEVdAkUqyn7%2BETzqJdEs68%2FQe5HeWZvOt1j68JZB5sXxxPIHLTWi0t1QYKmqiIz323lGBzdEwhPs51dHOPe2fpJtGyeEiZn%2F%2FnhulLlPE4At02fpHYmdtfwWpHWayYWCQCAtBurs7hMVqg48V2HZxMTy7KJNEJiZg39YGAInPKnW
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.