JCrypt
Aliases: RIP lmao, Locked, Daddycrypt, Omero, Crypted, Ncovid, NotStonks, Iam_watching, Vn_os, Wearefriends, MALWAREDEVELOPER, MALKI, Poison, Foxxy, Mafiaware666
- First seen
- 2020-03-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-17 02:00:04
- Profile updated
- 2026-07-07 13:48:18
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications retail-and-hospitality
Context
Ransomware written in C#. Fortunately, all current versions of the MafiaWare666 ransomware are decryptable. The Threat Lab from Avast has developed a free decryption tool for this malware.
Detection coverage
- 2 YARA rules
Detection rules
- MALPEDIA_Win_Poison_Ivy_Auto (yara-rule)
- MALPEDIA_Win_Poison_Rat_Auto (yara-rule)
Reports & references
- id-ransomware.blogspot.com — Jcrypt Ransomware (report)
- twitter.com — 1342027328063295488 (report)
- twitter.com — 1380610583603638277 (report)
- decoded.avast.io — Decrypted Mafiaware666 Ransomware (report)
- files.avast.com — Avast Decryptor Mafiaware666.Exe (report)