Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

Sophisticated Ransomware Targets AI Model Weights but Fails to Collect Ransom

A persistent attacker breached the same Langflow server twice, evolving their ransomware to specifically destroy trained AI models. The vulnerability exploited, CVE-2025-3248, allows unauthorized Python execution on the server. The initial attack encrypted configuration items, while the later one deployed ENCFORGE, a ransomware designed for AI assets, targeting specific AI model files like PyTorch, TensorFlow checkpoints, and various AI data formats. Despite its destructive intent, ENCFORGE lacks the ability to exfiltrate data or demand ransom payments effectively, rendering it a wiper.

The impact is severe; restoring AI models is costly and complex, with losses far beyond typical database restorations, making this a critical business risk often underestimated in cybersecurity budgets. The ransomware leveraged built-in shortcuts, such as the Docker socket, to escape containers and execute rapidly, reflecting sophisticated adversary tactics. This threat highlights glaring gaps in patch management, as the exploited vulnerability remained unpatched for over fourteen months.

Experts stress that AI model weights require explicit inclusion in backup and recovery plans. Immediate recommended actions include updating all exposed Langflow instances, securing Docker sockets, naming model artifacts in backups, rotating exposed credentials, and monitoring suspicious file encryptions. This case marks a new frontier where ransomware is purpose-built for AI environments, demanding urgent attention from security and business leaders alike.

Venturebeat
Venturebeat