'Jaff' Enters the Ransomware Scene, Locky-Style

ForcePoint Security Labs have observed today a major malicious email campaign from the Necurs botnet spreading a new ransomware which appears to call itself 'Jaff', peaking within our telemetry at nearly 5m emails per hour.

The emails sent by this campaign may look spartan to the professional eye but, as ever, the human point of interaction with systems is the most vulnerable: by potentially reaching so many individuals, campaigns such as this can - and do - succeed in infecting people. Add to this a ransom of 1.79 Bitcoins (approximately $3,300 at the time of the campaign) and the potential 'value' of the campaign is significant.

Article Link: https://blogs.forcepoint.com/security-labs/jaff-enters-ransomware-scene-locky-style

https://blog.malwarebytes.com/cybercrime/2017/05/new-jaff-ransomware-via-necurs-asks-for-2-btc/

https://www.virustotal.com/en/file/b6e1b1729d321be66cf9f9b2a09977550feb2dceb7d80bd526c7332e17cdf12d/analysis/

https://www.virustotal.com/en/file/1836679b61d113e71c1818f654742c18bc23d7a4c0208881163fbf612a39f3c2/analysis/

https://www.virustotal.com/en/file/42cfc10a1dbc81978abcfa3e9b8916267edc144207e77724efaf985ea85a1214/analysis/

https://www.virustotal.com/en/file/5bd8352171880485bf06d2d089e39d4112e8540f28d0f84bb045ab58737ad6bf/analysis/