Description
Jaff is a ransomware family distributed through malspam by the crews behind the Dridex, Locky, and Bart distributions, later associated with the TA505 group's broader activity. Researchers have since published a decryptor that recovers files encrypted by the family.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Binary.Ransomware.Jaff |
| Win32.Ransomware.Jaff |