Overview
A heavily upgraded ransomware payload called ENCFORGE, deployed by an autonomous AI-driven threat actor designated JADEPUFFER, has emerged as a serious and novel threat to organisations running custom artificial intelligence pipelines. First documented in early July 2026, JADEPUFFER returned on 20 July 2026 with a campaign that demonstrated an alarming degree of autonomous problem-solving capability, completing a full container escape and encryption sequence in under six minutes without human direction. Michael Clark, Director of Threat Research at Sysdig, described the objective of ENCFORGE as destroying “the one thing an organisation cannot simply restore” โ a characterisation that points to a fundamental shift in the logic of cyber extortion.
Unlike conventional ransomware that targets databases, file servers, or backup repositories for financial leverage, ENCFORGE is a compiled Go binary engineered specifically to locate and permanently destroy the core assets of modern machine learning stacks: model weights, training checkpoints, vector databases, and curated training datasets. Critically, the payload functions as a pure wiper rather than traditional ransomware. The encryption key is generated at random, printed once to the console, and never saved or transmitted โ meaning there is no payment mechanism and no recovery pathway once the payload executes. This design removes the financial negotiation element entirely and replaces it with guaranteed, irreversible destruction.
For professional services firms, consulting practices, legal technology teams, and environmental and engineering organisations that have invested in building proprietary AI pipelines, this development is directly relevant to business continuity planning. The cost of rebuilding a single production-ready fine-tuned model โ accounting for cloud GPU time and engineering labour โ is estimated at between USD 75,000 and USD 500,000 (approximately AUD 115,000 to AUD 770,000 at current exchange rates). These are not abstract losses recoverable from a snapshot; they represent months of computational work and specialist human effort that cannot be reconstituted from standard backup routines.
Key details of ENCFORGE: attack chain, encryption methodology, and targeted file types
ENCFORGE targets 180 specific file extensions associated with AI and machine learning workflows. These include PyTorch model files (.pt, .pt2, .pth), Hugging Face SafeTensors (.safetensors), llama.cpp quantised model formats (.ggml, .gguf), training dataset formats including Apache Arrow (.arrow), Feather (.feather), Parquet (.parquet), and TensorFlow records (.tfrecord), NumPy array files (.npy, .npz), training checkpoints (.ckpt), and Facebook AI Similarity Search indices (.faiss). The precision of this target list demonstrates that ENCFORGE was built by adversaries with detailed working knowledge of how modern AI development environments are structured and where their highest-value assets reside.
The encryption methodology uses a hybrid scheme combining AES-256-CTR symmetric encryption with RSA-2048 key wrapping. This is a robust and well-understood cryptographic approach that, under normal circumstances, would be used to secure data. In ENCFORGE’s implementation, however, the critical distinction is that the malware carries no outbound network code whatsoever. The RSA-wrapped key is never exfiltrated to a command-and-control server, never uploaded to a leak site, and never associated with a payment portal. It is displayed once at the console during execution and then lost permanently. This makes ENCFORGE technically a wiper, not ransomware in the classical sense, regardless of the encryption mechanism used.
The attack chain begins at internet-facing Langflow servers that have not been patched against known remote code execution vulnerabilities. The primary vulnerability exploited is CVE-2025-3248, which involves unauthenticated remote code execution via Langflow’s code validation endpoint. The campaign conducted on 20 July 2026 also incorporated CVE-2026-0770, an RCE vulnerability via the exec_globals parameter, rated 9.8 on the CVSS scale and added to CISA’s Known Exploited Vulnerabilities catalogue on 21 July 2026. Once initial access is achieved, the attacker harvests any AI provider API keys โ including credentials for OpenAI, Anthropic, and Hugging Face โ stored in Langflow’s runtime environment. In the July 2026 campaign, after encountering an initial payload-fetch failure, the JADEPUFFER agent autonomously generated six custom Python scripts within 5 minutes and 24 seconds to construct a privileged escape container via an exposed Docker socket, copy ENCFORGE across the namespace boundary using procfs, trigger the encryption routine, and verify execution success. This level of autonomous recovery behaviour in an offensive tool represents a materially different threat model than conventional automated malware.
Mitigation requires action across several layers. Langflow instances must be updated to version 1.3.0 or later to close the unauthenticated RCE vulnerabilities. Access to the Docker socket at /var/run/docker.sock must be restricted to prevent the container escape technique used in the July 2026 campaign. AI provider API credentials must never be stored in Langflow’s runtime environment. Model weights, training checkpoints, and curated datasets must be held in isolated, read-only, offline backup systems that are structurally separate from production AI infrastructure โ standard cloud snapshot policies do not satisfy this requirement.

Australian context: AI pipeline security and business continuity for professional services
Australian professional services organisations โ including engineering and environmental consultancies, legal practices, planning firms, and government agencies โ are increasingly deploying custom AI pipelines to support document analysis, regulatory interpretation, and technical reporting workflows. Where these pipelines incorporate proprietary fine-tuned models or curated datasets built from years of project work, the assets at risk from ENCFORGE-class payloads are not recoverable through standard incident response procedures. Business continuity planning for these environments must now account explicitly for the permanent destruction of AI model assets as a distinct threat category, separate from data theft or service disruption.
References and related sources
- Primary source: venturebeat.com
- scworld.com
- sysdig.com
- infosecurity-magazine.com
- cve.org
How iEnvi can help
iEnvi integrates technology and data-driven approaches into environmental consulting. We monitor AI and technology developments that affect how environmental professionals deliver services to clients.
This is an iEnvi Machete news summary. Prepared by iEnvi to summarise the source article for environmental professionals tracking AI, data, and technology developments that affect consulting and project delivery.
Published: 28 Jul 2026
Need advice on this topic? Speak to an iEnvi expert at info@ienvi.com.au or 1300 043 684, or contact us online.
Need advice on this issue? iEnvi provides practical, senior-led environmental consulting across contaminated land, remediation, ecology and environmental risk.
Contaminated land advice Remediation services Discuss your site Talk to iEnvi