When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain
Brief
By Crystal Morin
Ransomware crews have always followed the money. For years, that meant targets like banks and hospitals organizations with high-value assets and sensitive data who couldn’t afford downtime. Now, it means AI models too.
A threat actor the Sysdig Threat Research Team (TRT) dubbed JADEPUFFER has already shown us where the future of ransomware is heading.
In the span of a few weeks, JADEPUFFER went from poorly executed (albeit successful) database extortion with throwaway scripts to deploying a compiled ransomware binary built for one purpose: destroying AI and machine learning (ML) assets.
That progression tells us what attackers now consider valuable.
From on-the-fly to a purpose-built weapon
JADEPUFFER’s first campaign was scrappy, but it worked.
