Categories: NewsSecurity

Jaff Ransomware Demands a Two Bitcoin Payment to Decrypt Files

Ransomware comes in many different shapes and sizes. Some malware strains are rather easy to remove free of charge, whereas others can be a real pain in the rear. Jaff, a new type of ransomware, is perhaps one of the most expensive types of malware we have seen in quite some time. It demands a ransom of $3,700 to be paid in Bitcoin, which is a rather steep amount.

Jaff Ransomware Swings For The Fences

It is evident criminals who rely on ransomware distribution are looking to make a lot of money in quick succession. That is much easier said than done, though, as security researchers often come up with free decryption tools to nullify these threats.  However, in the case of Jaff,  there is no free decryption option whatsoever right now.

Similarly to virtually any other type of ransomware, the Jaff malware encrypts files and gives them a custom file extension. It appears the files are encrypted using AES, which has become the norm over the past few months. It also appears Jaff shares a lot of similarities with Locky, at least here the payment page is concerned. That is rather interesting, although Jaff demands a much higher amount compared to Locky.

This brings us to what puts Jaff on the radar of security researchers right now. The malware demands victims to pay $3,700 worth of Bitcoin to have the files restored. It is rated unusual for ransomware types to charge such a steep amount, considering most consumers won’t spend that amount of money on recovering their files. Then again, people who are genuinely worried about losing sensitive files may be tricked into paying the ransom in the end.

Related Post

Regarding the distribution of Jaff ransomware, it appears the malware is actively distributed through MALSPAM traffic originating from the Necurs botnet. People who have been following our ransomware coverage may recall the Necurs name, as it is a popular botnet to distribute malware on a rather large scale. Spam email campaigns have been a very popular tool among cybercriminals over the past few years, and it looks like things will not change anytime soon.

To be more specific, the Jaff ransomware is hidden in a malware-laden email attachment that requires users to enable macros in Microsoft Word. Once the user does so, they will download multiple malicious files on their machine, including the Jaff payload itself.  As soon as the download is finished, the files on the computer will be encrypted. Breaking this encryption is impossible right now unless the money is paid.

Demand of a $3, 700 payment in Bitcoin is rather unusual, to say the least. This aggressive method by the criminals will make their ransomware a type priority for security researchers to decrypt with a free tool, though. It is doubtful anyone would pay 2 Bitcoin to restore file access. It is unclear if files can be restored from a previous backup, though, as most ransomware types often delete shadow volume copies as well.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Top Crypto Coins to Buy in May 2024: TON, LINK, and KANG in the Spotlight

Historically, extended periods of market downturn have often preceded a resurgence in crypto prices, ultimately…

7 hours ago

The Rise of BEFE Coin: Today’s Must-Have Meme Coin Investment

Discover the charm of BEFE Coin, a special meme coin today. As it starts catching…

7 hours ago

Experts Predict Significant Gain in Bitgert Coin Price This Week

Many investors are always careful about wanting to invest in any crypto project because of…

7 hours ago

BlockDAG Excels With 30,000x ROI Potential, Outshining NEAR Protocol’s Price Gain And Render Token’s Emerging Promise

Render Token is advancing with significant updates like OctaneBench integration and a new pricing algorithm,…

20 hours ago

Comparing Generative AI Cryptos SingularityNET, Akash Network, and Raboo 

Projects all across the crypto market began integrating cutting-edge technology as a core part of…

1 day ago

Wormhole Brings More Interoperability to Arbitrum; KangaMoon and Optimism Eye Bullish Rally As Top Altcoins

Wormhole has recently taken some big steps towards improving compatibility on Arbitrum (ARB). At the…

1 day ago