JCry is a Windows ransomware family that encrypts victim files and demands payment in Bitcoin for decryption. It has been observed relying on user execution, including lures masquerading as an Adobe Flash Player update installer, to trigger infection. Execution chains associated with JCry use Windows scripting and command interpreters, including PowerShell, VBScript, and cmd.exe launching PowerShell, indicating a script-driven deployment model.
For persistence, JCry has been observed placing payloads in the Windows Startup directory so it will run again after reboot or user logon. To increase impact and hinder recovery, it deletes shadow copies, a common anti-recovery behavior used by ransomware to make restoration more difficult without backups. The combination of file encryption, persistence through startup-folder placement, script-based execution, and shadow-copy deletion is consistent with financially motivated ransomware operations targeting Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
APT19 used PowerShell commands to execute payloads... APT28 downloads and executes PowerShell scripts... APT29 has used encoded PowerShell scripts... | used PowerShell commands to execute payloads
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Multiple ransomware families and actors are described as encrypting victim filesystems/drives for extortion (e.g., Akira, Conti, Ryuk, WannaCry, NotPetya, etc.), often appending new extensions and dropping ransom notes.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that deletes shadow copies to prevent easy data restoration.
Uses VBS scripts.
Malware that uses PowerShell to execute payloads.
Ransomware that maintains persistence by placing payloads in the Startup directory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.