Trusted Design

Jaff Ransomware and Suspicious PDF Delivery

概要

Forcepoint Security Labs™ have observed today a major malicious email campaign from the Necurs botnet spreading a new ransomware which appears to call itself 'Jaff', peaking within our telemetry at nearly 5m emails per hour. The emails sent by this campaign may look spartan to the professional eye but, as ever, the human point of interaction with systems is the most vulnerable: by potentially reaching so many individuals, campaigns such as this can - and do - succeed in infecting people. Add to this a ransom of 1.79 Bitcoins (approximately $3,300 at the time of the campaign) and the potential 'value' of the campaign is significant.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Scattered Spider

Score: 13.25
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1598.003 - Spearphishing Link
  • T1657 - Financial Theft
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

FIN4

Score: 6.45
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

BlackTech

Score: 3.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

MuddyWater

Score: 3.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

LuminousMoth

Score: 3.42
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
MITREへのリンク →

Confucius

Score: 3.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Kimsuky

Score: 18.51
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
  • T1657 - Financial Theft
  • T1593 - Search Open Websites/Domains
  • T1566 - Phishing
MITREへのリンク →

Sidewinder

Score: 12.49
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Elderwood

Score: 3.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

FIN7

Score: 6.89
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1124 - System Time Discovery
MITREへのリンク →

Mustard Tempest

Score: 3.42
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
MITREへのリンク →

Sandworm Team

Score: 15.15
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1584.005 - Botnet
  • T1593 - Search Open Websites/Domains
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Transparent Tribe

Score: 3.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Mustang Panda

Score: 14.20
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
  • T1593 - Search Open Websites/Domains
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT32

Score: 8.25
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Lazarus Group

Score: 12.55
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Leviathan

Score: 6.48
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT33

Score: 3.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

ZIRCONIUM

Score: 6.50
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1124 - System Time Discovery
MITREへのリンク →

EXOTIC LILY

Score: 8.31
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Magic Hound

Score: 9.09
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1586.002 - Email Accounts
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 10.98
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Windshift

Score: 4.84
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Cobalt Group

Score: 3.81
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT29

Score: 9.00
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1203 - Exploitation for Client Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

TA2541

Score: 4.29
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
MITREへのリンク →

Earth Lusca

Score: 3.42
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
MITREへのリンク →

Storm-1811

Score: 8.51
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.004 - Spearphishing Voice
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Turla

Score: 4.04
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1124 - System Time Discovery
MITREへのリンク →

TA577

Score: 4.11
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1586.002 - Email Accounts
MITREへのリンク →

Patchwork

Score: 6.27
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

TA505

Score: 4.29
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
MITREへのリンク →

LazyScripter

Score: 4.29
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
MITREへのリンク →

APT42

Score: 3.42
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1608.001 - Upload Malware
MITREへのリンク →

APT28

Score: 11.63
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1203 - Exploitation for Client Execution
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Star Blizzard

Score: 14.88
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
  • T1593 - Search Open Websites/Domains
MITREへのリンク →

Moonstone Sleet

Score: 7.83
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

CURIUM

Score: 8.45
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1124 - System Time Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dragonfly

Score: 8.45
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1566.001 - Spearphishing Attachment
  • T1598.002 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Saint Bear

Score: 4.34
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

FIN6

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BRONZE BUTLER

Score: 4.96
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Threat Group-3390

Score: 8.47
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1608.002 - Upload Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Darkhotel

Score: 4.96
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

BITTER

Score: 4.34
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ajax Security Team

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Higaisa

Score: 4.96
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Malteiro

Score: 3.40
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1657 - Financial Theft
MITREへのリンク →

SideCopy

Score: 6.47
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
MITREへのリンク →

APT37

Score: 5.99
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

IndigoZebra

Score: 3.54
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1586.002 - Email Accounts
MITREへのリンク →

APT38

Score: 4.50
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

The White Company

Score: 4.96
Matched TTPs:
  • T1566.001 - Spearphishing Attachment
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

HEXANE

Score: 4.64
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1608.001 - Upload Malware
MITREへのリンク →

LAPSUS$

Score: 6.80
Matched TTPs:
  • T1586.002 - Email Accounts
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Contagious Interview

Score: 10.30
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1657 - Financial Theft
  • T1593 - Search Open Websites/Domains
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Medusa Group

Score: 19.35
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1657 - Financial Theft
  • T1650 - Acquire Access
  • T1529 - System Shutdown/Reboot
  • T1218.014 - MMC
MITREへのリンク →

HAFNIUM

Score: 3.62
Matched TTPs:
  • T1584.005 - Botnet
MITREへのリンク →

Axiom

Score: 8.40
Matched TTPs:
  • T1584.005 - Botnet
  • T1566 - Phishing
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Volt Typhoon

Score: 9.50
Matched TTPs:
  • T1584.005 - Botnet
  • T1593 - Search Open Websites/Domains
  • T1124 - System Time Discovery
MITREへのリンク →

INC Ransom

Score: 5.81
Matched TTPs:
  • T1657 - Financial Theft
  • T1566 - Phishing
MITREへのリンク →

AppleJeus

Score: 5.81
Matched TTPs:
  • T1657 - Financial Theft
  • T1566 - Phishing
MITREへのリンク →

Sea Turtle

Score: 4.78
Matched TTPs:
  • T1566 - Phishing
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

GOLD SOUTHFIELD

Score: 3.29
Matched TTPs:
  • T1566 - Phishing
MITREへのリンク →

UNC3886

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Velvet Ant

Score: 4.13
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Medusa Group

Score: 0.86
Matched TTPs:
  • T1218.014 - MMC
  • T1608.002 - Upload Tool
  • T1657 - Financial Theft
  • T1650 - Acquire Access
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Kimsuky

Score: 0.77
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1657 - Financial Theft
  • T1593 - Search Open Websites/Domains
  • T1608.001 - Upload Malware
  • T1566 - Phishing
  • T1598.003 - Spearphishing Link
  • T1586.002 - Email Accounts
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Sandworm Team

Score: 0.68
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1593 - Search Open Websites/Domains
  • T1566.001 - Spearphishing Attachment
  • T1608.001 - Upload Malware
  • T1598.003 - Spearphishing Link
  • T1584.005 - Botnet
MITREへのリンク →

Star Blizzard

Score: 0.66
Matched TTPs:
  • T1593 - Search Open Websites/Domains
  • T1608.001 - Upload Malware
  • T1598.003 - Spearphishing Link
  • T1586.002 - Email Accounts
  • T1598.002 - Spearphishing Attachment
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Mustang Panda

Score: 0.62
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1593 - Search Open Websites/Domains
  • T1608.001 - Upload Malware
  • T1598.003 - Spearphishing Link
  • T1586.002 - Email Accounts
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Scattered Spider

Score: 0.60
Matched TTPs:
  • T1578.002 - Create Cloud Instance
  • T1564.008 - Email Hiding Rules
  • T1657 - Financial Theft
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Lazarus Group

Score: 0.57
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
  • T1529 - System Shutdown/Reboot
  • T1566.003 - Spearphishing via Service
  • T1566.001 - Spearphishing Attachment
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る