Netskope Threat Labs

JaffCrypt

ATP Sandbox Adv. HeuristicsAV

JaffCrypt refers to detections of the Jaff ransomware, which spread in 2017 through PDF attachments with embedded links in campaigns distributed by the Necurs botnet. It demanded a ransom for file decryption, and its campaigns showed how botnet driven spam could push ransomware to large audiences in short bursts.

First seen
May 2023
Last seen
October 2026
Alert Name
Document-Word.Ransomware.JaffCrypt
Gen:Variant.Ransom.JaffCrypt.2
Trojan.Ransom.JaffCrypt.B
Win32.Ransomware.JaffCrypt