Categories: NewsSecurity

Jaff Ransomware Demands a Two Bitcoin Payment to Decrypt Files

Ransomware comes in many different shapes and sizes. Some malware strains are rather easy to remove free of charge, whereas others can be a real pain in the rear. Jaff, a new type of ransomware, is perhaps one of the most expensive types of malware we have seen in quite some time. It demands a ransom of $3,700 to be paid in Bitcoin, which is a rather steep amount.

Jaff Ransomware Swings For The Fences

It is evident criminals who rely on ransomware distribution are looking to make a lot of money in quick succession. That is much easier said than done, though, as security researchers often come up with free decryption tools to nullify these threats.  However, in the case of Jaff,  there is no free decryption option whatsoever right now.

Similarly to virtually any other type of ransomware, the Jaff malware encrypts files and gives them a custom file extension. It appears the files are encrypted using AES, which has become the norm over the past few months. It also appears Jaff shares a lot of similarities with Locky, at least here the payment page is concerned. That is rather interesting, although Jaff demands a much higher amount compared to Locky.

This brings us to what puts Jaff on the radar of security researchers right now. The malware demands victims to pay $3,700 worth of Bitcoin to have the files restored. It is rated unusual for ransomware types to charge such a steep amount, considering most consumers won’t spend that amount of money on recovering their files. Then again, people who are genuinely worried about losing sensitive files may be tricked into paying the ransom in the end.

Related Post

Regarding the distribution of Jaff ransomware, it appears the malware is actively distributed through MALSPAM traffic originating from the Necurs botnet. People who have been following our ransomware coverage may recall the Necurs name, as it is a popular botnet to distribute malware on a rather large scale. Spam email campaigns have been a very popular tool among cybercriminals over the past few years, and it looks like things will not change anytime soon.

To be more specific, the Jaff ransomware is hidden in a malware-laden email attachment that requires users to enable macros in Microsoft Word. Once the user does so, they will download multiple malicious files on their machine, including the Jaff payload itself.  As soon as the download is finished, the files on the computer will be encrypted. Breaking this encryption is impossible right now unless the money is paid.

Demand of a $3, 700 payment in Bitcoin is rather unusual, to say the least. This aggressive method by the criminals will make their ransomware a type priority for security researchers to decrypt with a free tool, though. It is doubtful anyone would pay 2 Bitcoin to restore file access. It is unclear if files can be restored from a previous backup, though, as most ransomware types often delete shadow volume copies as well.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Velocity Ticket Debuts As The AI-Powered Invoicing Tool Every Service Business Needs in 2026

Velocity Ticket is trying to fix a major gap in businesses, and the approach it…

2 days ago

Axelar Confirms $4.67M Exploit on Secret Network Bridge, Core Protocol Remains Unaffected

Axelar is moving fast to contain damage after identifying a security incident that has resulted…

3 days ago

Sui Synthetic Dollar suiUSDe Gets Its Own Website

suiUSDe now has a dedicated landing page. The token, officially the eSui Dollar, comes out…

3 days ago

Ventuals Winds Down HIP-3 DEX, vHYPE Withdrawals Now Live For All Holders

Ventuals has fully wound down its HIP-3 DEX, and vHYPE withdrawals are now open. The…

3 days ago

Avalanche Launches Payments Collective With Franklin Templeton And 25 Others

Avalanche has launched the Avalanche Payments Collective, bringing together 28 organizations spanning nearly every layer…

4 days ago

ASTER Whale Reopens 5x Long Days After Getting Fully Liquidated On The Same Token

A wallet tracked as 0x5f91 just opened a fresh 5x leveraged long on ASTER, putting…

4 days ago