New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Summary

A new ransomware variant named ENCFORGE has been discovered targeting AI model files, including weights, vector indexes, and training datasets. This ransomware is linked to a previously identified AI-agent-driven operator and was deployed in an attack exploiting a Remote Code Execution (RCE) vulnerability in Langflow.

IFF Assessment

FOE

The discovery of ransomware specifically designed to target and encrypt AI model files represents a significant threat to organizations relying on AI infrastructure.

Defender Context

Defenders should be aware of emerging threats like ENCFORGE that specifically target AI infrastructure, as these could lead to significant data loss and operational disruption. Protecting AI model files and the systems they reside on, along with securing RCE vulnerabilities in AI development platforms like Langflow, is crucial.

Read Full Story →