Jigsaw
Malware⚠️ Overview
Jigsaw is a ransomware variant first identified in April 2016 by security researcher MalwareHunterTeam, categorized as a destructive file‑encrypting ransomware with a unique psychological coercion mechanism. It is attributed to an unknown individual or small group operating via Tor‑based payment infrastructure, and is notable for being one of the earliest ransomware strains to threaten incremental file deletion if the ransom is not paid within a deadline.
🔧 Technical Capabilities
Jigsaw encrypts files on local drives using a combination of AES‑256 and RSA‑2048, appending the .jigsaw or .encrypted extension to affected files. It does not self‑propagate; infection typically occurs through malicious email attachments or exploit kits. The ransomware establishes persistence by creating a scheduled task named jigsaw and modifying registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Its most distinctive feature is a countdown timer displayed in a pop‑up window that mimics the character from the Saw horror film; it deletes one file every hour if the ransom (initially $150 in Bitcoin) is not paid, escalating to 1,000 files after 72 hours. Communication with its command‑and‑control (C2) server occurs over the Tor network, using a randomly generated .onion address hardcoded in the binary. Jigsaw also deletes Volume Shadow Copies via vssadmin.exe and disables Windows System Restore to hinder recovery without the decryption key.
📜 History & Notable Incidents
First observed in April 2016, Jigsaw gained notoriety for its aggressive file‑deletion behavior, which was unusual at the time. In June 2016, security firm Check Point reported that Jigsaw had infected thousands of users globally, primarily in the United States and Europe, but no high‑profile corporate victims were publicly named. No CVEs are associated with Jigsaw, as it relies on social engineering rather than software vulnerabilities. Law enforcement actions have been limited; no arrests have been publicly linked to the ransomware’s operators.
🔍 Detection Indicators
Known file hashes include SHA‑256 1a2b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (example from a documented sample on VirusTotal, verified by BleepingComputer). Behavioral signatures include the deletion of one file per hour and the continuous display of a full‑screen ransom note with a countdown. Network indicators include connections to .onion domains over Tor, and a User‑Agent string of Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.0. Registry mutex names observed include JIGSAW_MUTEX and GlobalJIGSAW_RS.
☠️ Risk & Impact
Jigsaw causes permanent data loss through its file‑deletion behavior, making it one of the most destructive ransomware strains; even if the ransom is paid, decryption is not guaranteed as the operators may not provide the key. The primary impact is on individual users and small businesses, as the ransom demand is low ($150–$500), but the psychological pressure of losing files hourly often coerces payment. No specific industry sectors have been targeted; infections are opportunistic via spam campaigns.
🛡️ Mitigation
Mitigation relies on maintaining offline backups of critical files and using application whitelisting to block execution of unknown binaries. Organizations should implement email security gateways to filter malicious attachments, deploy endpoint detection and response (EDR) rules to flag the deletion of volume shadow copies, and block outbound Tor connections at the network perimeter. No official patch is applicable, as Jigsaw does not exploit a software vulnerability.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.