Jigsaw is a Windows ransomware family first seen in 2016 and initially referred to as BitcoinBlackmailer. It became widely known for using imagery and language derived from the Saw film franchise, including Billy the Puppet, to intimidate victims and pressure rapid payment. The malware encrypts files, commonly appends the .fun extension, and presents a ransom interface that threatens escalating consequences over time, including progressive deletion of encrypted files, higher ransom demands, and eventual destruction of all affected data if payment is not made. Some variants also punish system restarts by deleting large numbers of files.
Jigsaw is implemented in .NET and has been observed copying itself into the user profile application-data area and displaying a dedicated blackmail window after encryption. The ransom interface can include options to list encrypted files and to request decryption, with some samples attempting to contact remote infrastructure to obtain or validate a decryption key. The family is notable for psychological extortion tactics rather than technical sophistication, using countdown timers, taunting messages, and themed visual elements to increase victim distress.
Observed delivery has included malicious downloads from file-hosting services and pornography-themed lures, and reporting has also associated ransomware infection risk with suspicious email attachments such as JavaScript files and macro-enabled documents in the broader context of Jigsaw activity. Jigsaw has also been discussed alongside other ransomware families because of superficially similar file-deletion behavior, but such links are weak and not sufficient to establish common authorship.
Jigsaw is also notable for poor cryptographic implementation in at least some analyzed samples. Researchers found that the encryption key was hardcoded in the binary, enabling file recovery through reverse engineering without paying the ransom. This design weakness, together with other implementation flaws, led to public decryptors becoming available and reduced the family’s effectiveness compared with more mature ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
But as the hours tick by, the malware will begin to delete files – first only a few, but the number will rise, as will the ransom needed to unencrypt them. After 72 hours, all of the files on the target computer will be deleted.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a previous ransomware example for comparison with WannaCry's TOR-based C2 design.
Ransomware written in .NET that encrypts files, appends the .fun extension, gradually deletes files, displays a ransom note themed around the Saw franchise, and queries a C2 server for a decryption key. The sample copies itself into %APPDATA% as drpbx.exe and firefox.exe. The analysis notes a critical design flaw: the encryption key is hardcoded in the binary, enabling recovery through reverse engineering.
DOWNLOAD FREE JIGSAW RANSOMWARE DECRYPTION TOOL
Jigsaw is mentioned only as another ransomware allegedly created by the same author, iCoreX.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.