JSWorm is a ransomware family first identified in 2019 that evolved through multiple rebrandings and code rewrites into a broader lineage commonly associated with Nemty, Nefilim, Offwhite, Telegram, Fusion, Milihpen, and Gangbang. It began as a public ransomware-as-a-service operation and later shifted to more private, targeted big-game-hunting intrusions. Multiple analyses assess these variants as stages of a single family based on shared cryptographic design, ransom-note conventions, and leak-site infrastructure.
Early JSWorm distribution included exploit-kit delivery, botnet-assisted distribution, fake payment pages, and spam campaigns. Later operations relied more on direct enterprise compromise through exposed remote access and exploitation of vulnerable internet-facing systems, including Citrix ADC, as well as insecure RDP access. The family became associated with double extortion: operators stole sensitive data before encryption and threatened publication on a leak site to pressure victims into paying.
Across its evolution, JSWorm and descendant variants demonstrated typical enterprise ransomware functionality, including file encryption, termination of processes and services, deletion of backups and shadow copies, disabling of recovery mechanisms, and clearing of event logs. Some variants also established persistence through autorun mechanisms. Early builds contained significant cryptographic and implementation flaws that enabled decryption without payment, but later variants improved their cryptography and operational maturity. Around 2020, parts of the family were rewritten, including a transition from C++ to Go in some variants, while later descendants returned to C++ in certain branches.
The family has been linked to ransomware operators and personas involved in Nemty and Nefilim activity, and broader reporting has associated the lineage with later operations such as Karma and Nokoyawa. Victimology indicates a strong focus on organizations rather than consumers, with engineering and manufacturing especially prominent among publicly listed victims, alongside energy, utilities, finance, professional services, transportation, and healthcare. Geographic targeting was global, with notable victim concentrations reported in China, the United States, and Vietnam.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
There is evidence of an initial breach via exploitation of vulnerable server-side software (Citrix ADC) and unsecure RDP access.
From its creation in 2019 until the first half of 2020, JSWorm was offered as a public RaaS and was observed propagating via: RIG exploit kit
The threat actors started targeting high-profile victims and manually operating inside the victim’s network, exfiltrating confidential data and threatening to leak it to intimidate the victim.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Referenced as a ransomware family to which Karma shows notable code and configuration similarities.
JSWORM is a ransomware family with multiple aliases, operated by organized cybercriminals and linked to several high-profile ransomware campaigns.
Ransomware-as-a-Service platform used for extortion and data encryption attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.