jsworm logo

jsworm

0 incidentes 0 paises 0 sectores ransomware RU Ultimo: -
Aliases: Nefilim, Nemty
Ver en IntelTracker → APTTrail →
JSWorm is a financially motivated ransomware group that first emerged in January 2019. Initially operating as a public Ransomware-as-a-Service (RaaS) platform, the group evolved its operational model by early 2020 to focus on more targeted "big-game hunting" attacks, shifting from mass-scale infections to private cooperation with affiliates. The group's primary motivation is financial gain through ransom payments. JSWorm is notably distinguished by its continuous evolution and frequent rebranding, having operated under various names including Nemty, Nefilim, Offwhite, Fusion, Milihpen, Gangbang, and Karma, often retaining underlying code similarities that allow researchers to track its lineage. The individual or entity behind JSWorm is a Russian-speaking threat actor known by the username "jsworm" (among other aliases like farnetwork and jingo), who was instrumental in developing the ransomware and managing its affiliate programs.

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
ransomware
Pais origen
RU
Motivacion
-
Impacto
57
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

AfghanistanArgentinaAmerican SamoaAustraliaBelgiumBrazilBelarusCanadaSwitzerlandChina

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingEnterprises & HoldingAccommodationAir TransportationManufacturingPublic AdministrationEducational ServicesData Processing ServicesEnergy & Utilities