ENCFORGE: New Go-Based Ransomware Targeting AI Infrastructure
A compiled Go ransomware designed to encrypt AI model files, vector indexes, and training datasets. Uses AES-256-CTR with RSA-2048 key wrapping. Targets…
A compiled Go ransomware designed to encrypt AI model files, vector indexes, and training datasets. Uses AES-256-CTR with RSA-2048 key wrapping. Targets…
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator first documented earlier this…
NadMesh is a Go-based botnet discovered in July 2026 that targets exposed AI services to steal cloud credentials and Kubernetes tokens. It…
Caeruleus is a free open-source toolkit from Praetorian that consolidates Bluetooth Low Energy testing into a single Go binary. It supports scanning,…
FlockWiper is a multi-pass wiper that overwrites the Windows drive with different data patterns. It was rewritten in Go for GigaWiper and…
Lambsys is a Go-based ELF executable used in cryptojacking campaigns targeting Langflow vulnerabilities. It terminates rival miners, disables security controls, establishes persistence,…
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages designed to deploy a Python-based information stealer on…
A cluster of malicious packages that use fake .woff2 font files to conceal JavaScript payloads. Tactically overlaps with TaskJacker and PolinRider, using…
Nextron Systems discovered 16 Go packages containing the same malware as the npm packages, targeting the Go ecosystem with a Python infostealer.
ENCFORGE is a compiled Go ransomware, built with Go 1.22.12.