SECURITY·중요도 8·2026. 07. 21.·The Hacker News
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
── KO ──────────────────
ENCFORGE 랜섬웨어가 AI 모델 파일을 타겟으로 하는 공격이 발견됐다.
Sysdig 연구자들이 Langflow 서버에서 발생한 두 번째 공격을 JADEPUFFER와 연결 지었다. 이 운영자는 AI 모델의 가중치, 벡터 인덱스, 훈련 데이터셋과 같은 파일을 암호화하는 새로운 Go 언어로 작성된 랜섬웨어 ENCFORGE를 배포하고 있는 것으로 보고되었다. 이 랜섬웨어는 호스트 파일 시스템 전반에 걸쳐 AI 인프라 파일을 공격한다.
── EN ──────────────────
ENCFORGE ransomware targets AI model files in a recent attack.
Researchers at Sysdig have linked a second attack on the Langflow server to JADEPUFFER. This operator has been observed deploying ENCFORGE, a new compiled Go ransomware that encrypts model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem. The ransomware poses a significant threat to AI-related assets.