Trusted Design

Jaff Ransomware Gets Makeover - SANS Internet Storm Center

概要

Since 2017-05-11, a new ransomware named Jaff has been distributed through malicious spam (malspam) from the Necurs botnet. This malspam uses PDF attachments with embedded Word documents containing malicious macros. Victims must open the PDF attachment, agree to open the embedded Word document, then enable macros on the embedded Word document to infect their Windows computers. Prior to Jaff, weve seen waves of malspam using the same PDF attachment/embedded Word doc scheme to push Locky ransomware. Prior to that, this type of malspam was pushing Dridex. With all the recent news about WannaCry ransomware, people might forget Jaff is an ongoing threat. Worse yet, some people might not know about it at all since its debut about 2 weeks ago. Jaff has already gotten a makeover, so an infected host looks noticeably different now. With that in mind, todays diary reviews a wave of malspam pushing Jaff ransomware from Tuesday 2017-05-23.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 11.35
Matched TTPs:
  • T1053.007 - Container Orchestration Job
  • T1091 - Replication Through Removable Media
  • T1588.001 - Malware
  • T1001 - Data Obfuscation
MITREへのリンク →

Mustang Panda

Score: 7.60
Matched TTPs:
  • T1053.007 - Container Orchestration Job
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

Mustard Tempest

Score: 6.51
Matched TTPs:
  • T1682 - Query Public AI Services
  • T1091 - Replication Through Removable Media
MITREへのリンク →

Sandworm Team

Score: 7.09
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1049 - System Network Connections Discovery
  • T1218.010 - Regsvr32
MITREへのリンク →

TA2541

Score: 5.12
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1001 - Data Obfuscation
MITREへのリンク →

LuminousMoth

Score: 4.57
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1550 - Use Alternate Authentication Material
MITREへのリンク →

OilRig

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

Gamaredon Group

Score: 9.66
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1061 - Graphical User Interface
  • T1200 - Hardware Additions
MITREへのリンク →

Threat Group-3390

Score: 6.62
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1001 - Data Obfuscation
  • T1218.010 - Regsvr32
MITREへのリンク →

BlackByte

Score: 11.34
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1586.003 - Cloud Accounts
  • T1550 - Use Alternate Authentication Material
  • T1001 - Data Obfuscation
MITREへのリンク →

BITTER

Score: 5.56
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
MITREへのリンク →

APT32

Score: 12.00
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1550 - Use Alternate Authentication Material
  • T1592.004 - Client Configurations
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
MITREへのリンク →

Saint Bear

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

Moonstone Sleet

Score: 5.26
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1491 - Defacement
MITREへのリンク →

Contagious Interview

Score: 5.59
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1586.003 - Cloud Accounts
MITREへのリンク →

FIN7

Score: 4.07
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1588.001 - Malware
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

Magic Hound

Score: 5.72
Matched TTPs:
  • T1586.003 - Cloud Accounts
  • T1588.001 - Malware
MITREへのリンク →

APT28

Score: 10.86
Matched TTPs:
  • T1586.003 - Cloud Accounts
  • T1550 - Use Alternate Authentication Material
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Dragonfly

Score: 7.24
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Patchwork

Score: 7.24
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1001 - Data Obfuscation
  • T1218.010 - Regsvr32
MITREへのリンク →

Axiom

Score: 7.71
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1049 - System Network Connections Discovery
  • T1218.010 - Regsvr32
MITREへのリンク →

Ember Bear

Score: 4.09
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1218.010 - Regsvr32
MITREへのリンク →

Lazarus Group

Score: 6.18
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
MITREへのリンク →

FIN6

Score: 4.69
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1588.001 - Malware
MITREへのリンク →

menuPass

Score: 5.74
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1001 - Data Obfuscation
MITREへのリンク →

Leviathan

Score: 4.09
Matched TTPs:
  • T1550 - Use Alternate Authentication Material
  • T1218.010 - Regsvr32
MITREへのリンク →

Fox Kitten

Score: 5.38
Matched TTPs:
  • T1491 - Defacement
  • T1588.001 - Malware
MITREへのリンク →

Volt Typhoon

Score: 6.91
Matched TTPs:
  • T1491 - Defacement
  • T1049 - System Network Connections Discovery
MITREへのリンク →

APT38

Score: 3.29
Matched TTPs:
  • T1491 - Defacement
MITREへのリンク →

Scattered Spider

Score: 7.13
Matched TTPs:
  • T1491 - Defacement
  • T1556.008 - Network Provider DLL
MITREへのリンク →

Chimera

Score: 3.29
Matched TTPs:
  • T1491 - Defacement
MITREへのリンク →

APT29

Score: 13.72
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1556.008 - Network Provider DLL
  • T1218.010 - Regsvr32
  • T1218.009 - Regsvcs/Regasm
MITREへのリンク →

BRONZE BUTLER

Score: 5.34
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1218.010 - Regsvr32
MITREへのリンク →

PROMETHIUM

Score: 6.23
Matched TTPs:
  • T1588.001 - Malware
  • T1547.015 - Login Items
MITREへのリンク →

UNC3886

Score: 7.72
Matched TTPs:
  • T1588.001 - Malware
  • T1547.015 - Login Items
  • T1218.010 - Regsvr32
MITREへのリンク →

Higaisa

Score: 3.59
Matched TTPs:
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
MITREへのリンク →

APT41

Score: 3.59
Matched TTPs:
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
MITREへのリンク →

HAFNIUM

Score: 3.62
Matched TTPs:
  • T1049 - System Network Connections Discovery
MITREへのリンク →

LAPSUS$

Score: 3.84
Matched TTPs:
  • T1556.008 - Network Provider DLL
MITREへのリンク →

Gorgon Group

Score: 3.15
Matched TTPs:
  • T1001 - Data Obfuscation
MITREへのリンク →

Confucius

Score: 4.65
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Tropic Trooper

Score: 4.65
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Inception

Score: 4.65
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

DarkHydrus

Score: 3.15
Matched TTPs:
  • T1200 - Hardware Additions
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Medusa Group

Score: 4.54
Matched TTPs:
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT29

Score: 0.81
Matched TTPs:
  • T1556.008 - Network Provider DLL
  • T1218.010 - Regsvr32
  • T1218.009 - Regsvcs/Regasm
  • T1592.004 - Client Configurations
MITREへのリンク →

BlackByte

Score: 0.72
Matched TTPs:
  • T1586.003 - Cloud Accounts
  • T1091 - Replication Through Removable Media
  • T1001 - Data Obfuscation
  • T1550 - Use Alternate Authentication Material
MITREへのリンク →

APT32

Score: 0.71
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
  • T1592.004 - Client Configurations
  • T1550 - Use Alternate Authentication Material
  • T1588.001 - Malware
MITREへのリンク →

Kimsuky

Score: 0.68
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1001 - Data Obfuscation
  • T1053.007 - Container Orchestration Job
  • T1588.001 - Malware
MITREへのリンク →

APT28

Score: 0.67
Matched TTPs:
  • T1586.003 - Cloud Accounts
  • T1200 - Hardware Additions
  • T1218.010 - Regsvr32
  • T1550 - Use Alternate Authentication Material
MITREへのリンク →

Gamaredon Group

Score: 0.59
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1200 - Hardware Additions
  • T1061 - Graphical User Interface
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る