Jaff
Malware⚠️ Overview
Jaff is a ransomware variant first discovered in May 2017 by Malwarebytes, part of the Locky ransomware family operated by the threat group known as the "Locky" developers (often linked to the Necurs botnet). It is categorized as a file-encrypting ransomware that demands payment in Bitcoin for decryption keys, targeting primarily Windows systems via email-based phishing campaigns.
🔧 Technical Capabilities
Jaff propagates through spam emails carrying malicious Word documents or JavaScript attachments that download the ransomware payload from compromised servers. It uses a custom C2 infrastructure hosted on Tor and clearnet domains to receive encryption keys and exfiltrate system information. Persistence is achieved by modifying the Windows Registry Run keys and creating scheduled tasks. Evasion techniques include anti-analysis checks for sandbox environments, process hollowing, and code obfuscation using PowerShell scripts. The ransomware encrypts over 100 file types using RSA-2048 and AES-128 encryption, renaming files with the .jaff extension and leaving ransom notes (e.g., "How_to_decrypt.html") in each folder.
📜 History & Notable Incidents
Jaff first emerged in May 2017, replacing Locky in spam campaigns distributed via the Necurs botnet. A notable incident in June 2017 saw a wave of Jaff emails targeting healthcare and education sectors in the US and UK. No specific CVEs were exploited; it relied on user interaction with malicious attachments. Law enforcement actions against the Necurs botnet in August 2019 disrupted Jaff distribution, but variants continue to circulate.
🔍 Detection Indicators
Known file hashes include MD5: a3c8f7e2b1d4... (example); behavioral signatures include encrypted files with .jaff extension and ransom note creation. Network IOCs include C2 domains like "malicious[.]top" and "paysign[.]cc", User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36", and mutex names like "Global\JaffMutex". Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun contain "Jaff" or random strings.
☠️ Risk & Impact
Jaff causes irreversible file encryption leading to data loss and operational disruption. Financial losses have been estimated at over $1 million from ransom payments in 2017-2018, primarily affecting healthcare, education, and small businesses. No data exfiltration capability has been publicly documented; the primary impact is denial of access to critical files.
🛡️ Mitigation
Recommended defenses include disabling macro execution in Office documents using GPO, implementing email filtering with attachment scanning, and maintaining offline backups. Detection rules are available in MITRE ATT&CK (T1486 - Data Encrypted for Impact) and Sigma rules for ransomware behavior. No specific patches exist; prevention relies on user awareness and endpoint protection solutions like Malwarebytes Anti-Ransomware.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.