Description
JaffCrypt refers to detections of the Jaff ransomware, which spread in 2017 through PDF attachments with embedded links in campaigns distributed by the Necurs botnet. It demanded a ransom for file decryption, and its campaigns showed how botnet driven spam could push ransomware to large audiences in short bursts.
Stats
- First seen
- May 2023
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Document-Word.Ransomware.JaffCrypt |
| Gen:Variant.Ransom.JaffCrypt.2 |
| Trojan.Ransom.JaffCrypt.B |
| Win32.Ransomware.JaffCrypt |