Jaff is a Windows ransomware family that emerged in 2017 and is closely associated with large-scale spam operations attributed to TA505 and infrastructure linked to the Necurs botnet. It was widely regarded as part of the same criminal ecosystem that distributed Dridex and Locky, and was introduced during a period when those operators were experimenting with successor ransomware strains and delivery tradecraft.
Jaff was primarily delivered through high-volume malicious email campaigns using invoice- or document-themed lures. Observed infection chains commonly used PDF attachments containing embedded Microsoft Word macro documents; when macros were enabled, the document downloaded and executed the ransomware payload. Campaigns were notable for their scale, reaching tens of millions of messages, and for the use of spoofed sender identities and social-engineering themes designed to induce document opening and macro execution.
Once executed, Jaff encrypts a broad range of victim files, including common business documents, archives, images, databases, media, source code, and virtual machine-related data. It appends characteristic new extensions to encrypted files and drops ransom notes in both HTML and bitmap form, directing victims to a Tor-based payment portal. The payment workflow and portal presentation showed strong operational similarities to earlier Locky and Bart ransomware operations, reinforcing assessments that the same or closely related actors were involved.
Jaff’s operational lifespan as a major spam-delivered ransomware family appears to have been relatively short. A flaw in its encryption implementation enabled the development of a public decryptor, after which observed Jaff spam activity declined and operators shifted back to other ransomware families, including Locky, and later to additional families used by TA505. Jaff remains notable as a transitional ransomware family in the evolution of TA505’s malware portfolio and as an example of rapid criminal adaptation in response to defender disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA505 aurait pratiqué un usage ponctuel d’autres rançongiciels (Bart, Jaff, Scarab, Philadelphia, GlobeImposter et GandCrab).
For example, in 2017 TA505 (also known as G0092, GOLD TAHOE) began using GlobeImposter in replacement of Jaff, GandCrab, and Snatch to extend the reach and effectiveness of their campaigns.
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
5 distinct techniques documented for this family, organized by ATT&CK tactic.
...embedded Microsoft Word documents with macros that, if enabled, download Jaff ransomware.
The messages in this campaign purported to be: From "Joan <joan.1234@[random domain]>" ... with subject "Receipt to print" and attachment "Sheet_321.pdf" ... Figure 3: The Microsoft Word document embedded inside the PDF | ...embedded Microsoft Word documents with macros that, if enabled, download Jaff ransomware.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family that encrypts files and may append .jaff, .wlu, or .sVn.
Named as ransomware previously used by TA505 before GlobeImposter replaced it in campaigns.
Ransomware family mentioned as one of several strains historically deployed by TA505.
Ransomware payload distributed in TA505 spam campaigns (mentioned as part of TA505’s diverse payload set).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.