Jaff is a Windows ransomware family introduced in May 2017 and associated with the financially motivated threat actor TA505. It was distributed through high-volume malicious email campaigns supported by the Necurs botnet, including campaigns sending tens of millions of messages. Invoice, receipt, and document-themed lures carried PDF attachments containing embedded Microsoft Word documents. When recipients enabled macros, the documents downloaded the ransomware from external servers.
Jaff encrypts a broad range of file types, including documents, archives, images, databases, media, source code, and virtual machine files. It changes encrypted-file extensions and creates ransom notes directing victims to a Tor-based payment portal demanding bitcoin for decryption. Its payment portal resembled those used by Locky and Bart, and its distributors also operated campaigns delivering Locky and Dridex. In June 2017, Kaspersky released a free decryptor after discovering a weakness in Jaff's encryption implementation; Jaff distribution subsequently declined. Kaspersky's RakhniDecryptor supports recovery of files encrypted by Jaff.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment.
For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
5 distinct techniques documented for this family, organized by ATT&CK tactic.
...embedded Microsoft Word documents with macros that, if enabled, download Jaff ransomware.
...embedded Microsoft Word documents with macros that, if enabled, download Jaff ransomware. | The messages in this campaign purported to be: From "Joan <joan.1234@[random domain]>" ... with subject "Receipt to print" and attachment "Sheet_321.pdf" ... Figure 3: The Microsoft Word document embedded inside the PDF
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware named as part of TA505's historical arsenal, without further technical details.
Ransomware family that encrypts files and may append .jaff, .wlu, or .sVn.
Named as ransomware previously used by TA505 before GlobeImposter replaced it in campaigns.
One of the ransomware families explicitly used by TA505 to encrypt victim files and demand payment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.