Skip to main content
✓ Resolved↓ De-escalatingCyber

New Malware & Ransomware Target AI Development Infrastructure

Two new cyber threats, a malware variant and ENCFORGE ransomware, are confirmed to be actively targeting AI development infrastructure.

Impact
8.3
Confidence
High
Evidence
2 sig · 2 src
Trajectory
↓ De-escalating
First seen Jul 16·Updated Jul 21·Synthesized Jul 21
Export brief

Assessment

High confidence2/2 signals corroborated across 2 independent sources

Two new cyber threats, a malware variant and ENCFORGE ransomware, are confirmed to be actively targeting AI development infrastructure. The malware focuses on data exfiltration and sabotage, while ENCFORGE specifically encrypts AI model weights and training data by exploiting a Langflow vulnerability (CVE-2025-3248). This represents a clear escalation in specialized attacks against AI pipelines.

Why it matters — These attacks threaten the integrity, confidentiality, and availability of critical AI intellectual property and operational capabilities.

Established

  • ·Confirmed: A new malware strain targets AI coding environments for credential and proprietary data exfiltration, including a destructive 'death switch' capability.
  • ·Confirmed: ENCFORGE ransomware specifically encrypts AI model weights, vector indexes, and training datasets.
  • ·Confirmed: ENCFORGE exploits Langflow vulnerability CVE-2025-3248 to gain root access to AI infrastructure.
  • ·Confirmed: Both threats indicate a shift toward targeting the integrity and specialized components of AI development pipelines.

Indicators to watch

  • Identification of additional vulnerabilities in AI development frameworks being exploited by threat actors
  • Reports of successful data exfiltration or operational disruption from these new malware and ransomware variants
  • Development of patches or mitigation strategies for CVE-2025-3248 and other AI-specific vulnerabilities

Evidence

Confirmed · 2 independent sources · 2 signals · 2 independent sources · 1 high-credibility

Central claimNew malware variant targets AI development infrastructure for data exfiltration and sabotage50% on claim · mixed evidence

Corroborated1 · 1 src · best medium 82%
Context1 · 1 src · best low 54%

Topics malware · ai-security · cybersecurity · data-breach · infrastructure-security · ransomware · cve-2025-3248 · langflow

Discussion

Sign in to add a note, contribute a source, or challenge the assessment.