JCry
MITRE ATT&CK: S0389 View on attack.mitre.org
Aliases: JCry
- First seen
- 2019-04-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 15:07:42
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:il
Context
JCry is ransomware written in Go. It was identified as apart of the #OpJerusalem 2019 campaign.
Detection coverage
- 320 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- PowerShell (attack-pattern)
- Visual Basic (attack-pattern)
- Malicious File (attack-pattern)
- Windows Command Shell (attack-pattern)
- Inhibit System Recovery (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Jcry (report)
- twitter.com — 1101936940297924608 (report)
- twitter.com — 1102078898320302080 (report)
- MITRE ATT&CK — S0389 (report)
- carbonblack.com — Cb Tau Threat Intelligence Notification Jcry Ransomware Pretends To Be Adobe Flash Player Update Installer (report)