Jaff

First seen
2017-05-11 00:00:00
Malware type
ransomware, downloader
Family
Malware family
Last IoC activity
2026-07-21 22:50:07
Profile updated
2026-07-07 15:43:19

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector

Context

We recently observed several large scale email campaigns that were attempting to distribute a new variant of ransomware that has been dubbed "Jaff". Interestingly we identified several characteristics that we have previously observed being used during Dridex and Locky campaigns. In a short period of time, we observed multiple campaigns featuring high volumes of malicious spam emails being distributed, each using a PDF attachment with an embedded Microsoft Word document functioning as the initial downloader for the Jaff ransomware.

Detection coverage

  • 2 YARA rules

Detection rules

  • CAPE_Jaff (yara-rule)
  • MALPEDIA_Win_Jaff_Auto (yara-rule)

Reports & references

  • Cisco Talos — Jaff Ransomware (report)
  • bleepingcomputer.com — Jaff Ransomware Distributed Via Necurs Malspam And Asking For A 3 700 Ransom (report)
  • id-ransomware.blogspot.com — Jaff Ransomware (report)
  • ransomlook.io — Jaff (report)
  • Broadcom/Symantec — Jaff New Ransomware Spread Necurs Botnet (report)
  • blog.malwarebytes.com — Jaff Ransomware Analysis (report)
  • bleepingcomputer.com — Jaff Ransomware Infected Over 100000 Computers In Just A Few Days (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
  • blog.intel471.com — A Brief History Of Ta505 (report)
  • intel471.com — A Brief History Of Ta505 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Jaff (report)
  • malware-traffic-analysis.net — Index (report)
  • clairelevin.github.io — Jaff (report)
  • proofpoint.com — Jaff New Ransomware From Actors Behind Distribution Of Dridex Locky Bart (report)

External references