jsworm

First seen
2019-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:56:54

Targeted industries: energy-and-utilities healthcare-and-pharmaceutical manufacturing professional-services

Context

JSWorm is a ransomware family that first appeared in May 2019 and is notable for undergoing multiple rebrands and evolutions, later appearing under names such as Nemty, Nefilim, Offwhite, Fusion, and Milihpen. Initially, it was distributed via malicious spam emails containing JavaScript files, hence the “JS” in its name. Later versions moved to targeted intrusions, leveraging compromised RDP services and vulnerable network appliances for initial access. JSWorm encrypts files using AES-256 encryption with RSA-2048 for key protection and appends campaign-specific extensions (e.g., .JSWORM, .Nemty, .Nephilim). The group adopted a double-extortion model in its later stages, stealing data before encryption and threatening to leak it via Tor-hosted sites. Its victimology spans various sectors worldwide, including manufacturing, energy, healthcare, and professional services. The continuous rebranding suggests an effort to evade detection, disrupt attribution, and maintain pressure on victims.

Reports & references

  • ransomlook.io — Jsworm (report)
  • McAfee — Jsworm Nemty Rebrands To Avoid Detection (report)
  • bleepingcomputer.com — Jsworm Ransomware Rebrands To Nemty With New Encryption Routines (report)
  • Trend Micro — Nefilim Ransomware Shifts To Double Extortion (report)

External references