JadePuffer, an “agentic” malware campaign, is returning with updated ransomware designed specifically to disrupt AI systems. Multiple reports say the latest activity uses a variant referred to as EncForge (also described as ENCFORGE), which expands beyond earlier behaviors and focuses on damaging AI-related data assets.

According to the reports, the ransomware is aimed at encrypting and potentially destroying AI model artifacts, including training datasets, vector databases, and model checkpoints. This targeting strategy shifts the impact of the malware from traditional file encryption toward the kinds of data and storage used in machine-learning workflows.

The publications describe the campaign as an upgraded follow-on effort rather than an entirely new operator or campaign, indicating continuity between the original JadePuffer activity and the newer EncForge deployment. While details of delivery methods and victim counts are not covered in the provided excerpts, both sources describe the same core capability: JadePuffer’s autonomous components are configured to locate and encrypt AI assets as part of a ransomware routine.