JSWorm is a ransomware lineage first identified in 2019 that evolved from a public ransomware-as-a-service operation into a private, targeted extortion enterprise. The family is widely associated with successive rebrands and closely related variants including Nemty, Nefilim, Offwhite, Telegram, Fusion, Milihpen, and GangBang. Security reporting has also linked the intrusion set behind Nemty and early Nefilim activity to Water Roc, with underground personas including jsworm and Jingo associated with development and affiliate recruitment. Early JSWorm activity was distributed opportunistically through exploit kits, botnet delivery, fake payment sites, and spam. By 2020, the operators shifted toward big-game hunting, using exposed remote services and vulnerable internet-facing systems for initial access, including insecure RDP and exploitation of Citrix ADC vulnerabilities. In later intrusions, the operators conducted hands-on-keyboard activity characteristic of modern human-operated ransomware, including credential theft, Active Directory enumeration, lateral movement, data exfiltration, and staged ransomware deployment. The malware family underwent repeated technical redevelopment. Early variants used custom cryptographic implementations and contained flaws that enabled unpaid decryption, while later variants adopted stronger encryption schemes, revised configuration handling, and rewrites between C++ and Go. Across variants, the malware commonly terminated processes and services, deleted backups and shadow copies, cleared logs, established persistence through ransom-note or autorun mechanisms in some versions, and encrypted local drives and network-accessible data while excluding selected system-critical files to preserve host operability. From the Nemty and especially Nefilim phase onward, the operation became strongly associated with double extortion. Operators exfiltrated confidential data before encryption and used leak infrastructure to pressure victims over extended periods. Reporting attributes use of common post-exploitation tooling such as Cobalt Strike for command and control, Mimikatz for credential theft, PsExec for lateral movement, AdFind for directory reconnaissance, and cloud or FTP services for exfiltration. Nefilim in particular was noted for targeting large multinational enterprises and maintaining stable leak infrastructure. Victimology indicates broad international targeting, with notable victim concentrations reported in China, the United States, and Vietnam. Sector reporting shows a strong focus on engineering and manufacturing, with additional targeting of energy and utilities, financial organizations, transportation, healthcare, and other enterprise sectors. The family is also assessed to be closely related to later ransomware activity such as Karma, with strong code and operational similarities observed between Karma and the GangBang or Milihpen stage of the JSWorm lineage. Overall, JSWorm represents a mature ransomware ecosystem that progressed from commodity affiliate-driven distribution to targeted enterprise compromise, combining initial access through exposed services, credential theft and lateral movement, data exfiltration, and leak-site-backed double extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware family with code and configuration similarities to Karma.
KARMAの祖先として、Nokoyawaの系統説明の中で言及される関連グループ。
A ransomware operation that evolved from a public RaaS model in 2019 into a private big-game hunting/extortion operation by 2020, using data theft, leak-site pressure, and manual intrusion activity against high-profile victims.
Underground actor associated with Water Roc, previously advertising RazvRAT, JSWorm, and Nemty affiliate programs, and believed involved in Nefilim’s early development.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.