New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
A new ransomware variant named ENCFORGE has been discovered, specifically targeting AI model files. The ransomware exploits a remote code execution (RCE) vulnerability in Langflow, an open-source tool for building AI workflows. Once inside a system, ENCFORGE encrypts files with extensions such as .pkl, .h5, and .pt, which are commonly used for serialized models, Keras models, and PyTorch models, respectively. The attackers then demand a ransom payment in exchange for the decryption key. This incident highlights the growing trend of ransomware focusing on high-value AI assets, as trained models can be costly and time-consuming to reproduce. The attack vector via Langflow's RCE flaw underscores the importance of securing AI development pipelines. Organizations using Langflow should be aware that their model files could be targeted, leading to potential data loss and operational disruption.
ENCFORGE ransomware encrypts AI model files, threatening loss of valuable trained models for organizations using Langflow.