JSWorm is a ransomware family first identified in 2019 that evolved from a public ransomware-as-a-service operation into a private, human-operated enterprise focused on big-game hunting and double extortion. The family is widely associated with a lineage that includes Nemty and Nefilim and has also appeared under additional rebrands such as Offwhite, Telegram, Fusion, Milihpen, and Gangbang. Multiple analyses have linked these variants through shared cryptographic design, ransom-note conventions, leak-site infrastructure, and code lineage. The operation has also been associated with underground personas tied to later ransomware activity including Karma and Nokoyawa.
Early JSWorm campaigns were distributed opportunistically through the RIG exploit kit, the Trik botnet, fake payment websites, and spam campaigns. Later operations shifted toward targeted intrusions using exposed remote access and vulnerable edge infrastructure, including insecure RDP access and exploitation of Citrix ADC systems. This transition reflected a broader move from commodity ransomware distribution to manually operated attacks against larger organizations.
JSWorm’s functionality includes file encryption, termination of processes and services, deletion of backups and shadow copies, disabling of recovery mechanisms, and clearing of event logs. Later family variants also incorporated victim profiling and stronger cryptographic implementations. As the operation matured, operators increasingly separated intrusion activity from the encryptor itself, relying on manual post-compromise actions and third-party tooling while using the ransomware primarily as the final extortion stage.
A defining characteristic of the JSWorm lineage is its adoption of data theft and leak-site extortion. By 2020, the operators were running a leak platform used to pressure victims by threatening publication of stolen information. This placed JSWorm among the ransomware families that helped normalize double extortion as a standard criminal business model.
Victimology indicates a strong focus on enterprises, with engineering and manufacturing organizations prominently represented, alongside energy, utilities, finance, professional services, transportation, and healthcare. Reported victim distribution has included substantial activity in China, the United States, and Vietnam. The family is part of a broader ransomware ecosystem whose descendants and related operations continued to appear under new branding over time.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
There is evidence of an initial breach via exploitation of vulnerable server-side software (Citrix ADC) and unsecure RDP access.
From its creation in 2019 until the first half of 2020, JSWorm was offered as a public RaaS and was observed propagating via: RIG exploit kit
The threat actors started targeting high-profile victims and manually operating inside the victim’s network, exfiltrating confidential data and threatening to leak it to intimidate the victim.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Referenced as a ransomware family to which Karma shows notable code and configuration similarities.
JSWORM is a ransomware family with multiple aliases, operated by organized cybercriminals and linked to several high-profile ransomware campaigns.
Ransomware-as-a-Service platform used for extortion and data encryption attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.