Jaff
- First seen
- 2017-05-11 00:00:00
- Malware type
- ransomware, downloader
- Family
- Malware family
- Last IoC activity
- 2026-07-21 22:50:07
- Profile updated
- 2026-07-07 15:43:19
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector
Context
We recently observed several large scale email campaigns that were attempting to distribute a new variant of ransomware that has been dubbed "Jaff". Interestingly we identified several characteristics that we have previously observed being used during Dridex and Locky campaigns. In a short period of time, we observed multiple campaigns featuring high volumes of malicious spam emails being distributed, each using a PDF attachment with an embedded Microsoft Word document functioning as the initial downloader for the Jaff ransomware.
Detection coverage
- 2 YARA rules
Detection rules
- CAPE_Jaff (yara-rule)
- MALPEDIA_Win_Jaff_Auto (yara-rule)
Reports & references
- Cisco Talos — Jaff Ransomware (report)
- bleepingcomputer.com — Jaff Ransomware Distributed Via Necurs Malspam And Asking For A 3 700 Ransom (report)
- id-ransomware.blogspot.com — Jaff Ransomware (report)
- ransomlook.io — Jaff (report)
- Broadcom/Symantec — Jaff New Ransomware Spread Necurs Botnet (report)
- blog.malwarebytes.com — Jaff Ransomware Analysis (report)
- bleepingcomputer.com — Jaff Ransomware Infected Over 100000 Computers In Just A Few Days (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
- blog.intel471.com — A Brief History Of Ta505 (report)
- intel471.com — A Brief History Of Ta505 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Jaff (report)
- malware-traffic-analysis.net — Index (report)
- clairelevin.github.io — Jaff (report)
- proofpoint.com — Jaff New Ransomware From Actors Behind Distribution Of Dridex Locky Bart (report)