Jigsaw (ransomware)
Jigsaw (ransomware) is a type of malicious software that encrypts files on an infected system and demands a ransom for their release. It is known for its unique behavior of deleting files incrementally over time if the ransom is not paid. First discovered in 2016, Jigsaw is named after the character from the "Saw" movie franchise, which is used in its ransom note. As of October 2023, Jigsaw remains a notable example of ransomware due to its psychological tactics and destructive capabilities.
Overview
Jigsaw is a ransomware variant that encrypts files on a victim's computer and demands payment in exchange for the decryption key. What sets Jigsaw apart from other ransomware is its method of pressuring victims by threatening to delete files every hour until the ransom is paid. The ransomware also deletes a larger number of files if the victim attempts to terminate the process or restart the computer. This tactic increases the urgency and stress on the victim, aiming to coerce them into paying the ransom quickly.
History
Jigsaw was first identified in April 2016. It gained attention due to its aggressive file deletion strategy and the use of the "Saw" movie franchise imagery in its ransom note. The ransomware was initially distributed through spam emails containing malicious attachments. Over time, Jigsaw has been modified and updated by various threat actors, to multiple versions with slight variations in behavior and targeting.
Technical characteristics
Jigsaw encrypts files using the Advanced Encryption Standard (AES), a symmetric encryption algorithm widely used for its security and efficiency. Once executed, Jigsaw encrypts a wide range of file types, including documents, images, and databases. The ransomware appends a specific extension to the encrypted files, making it clear which files have been affected.
A unique feature of Jigsaw is its countdown timer, which begins as soon as the ransomware is executed. The timer is designed to create a sense of urgency, as it threatens to delete a certain number of files every hour until the ransom is paid. If the victim attempts to interfere with the ransomware process, such as by terminating it or restarting the computer, Jigsaw responds by deleting a larger number of files as a penalty.
Infection vector
Jigsaw primarily spreads through phishing emails that contain malicious attachments or links. These emails often appear to be from legitimate sources, tricking recipients into opening them. Once the attachment is opened or the link is clicked, the ransomware is downloaded and executed on the victim's system. Other potential infection vectors include compromised websites and exploit kits that take advantage of vulnerabilities in software to deliver the ransomware payload.
Notable campaigns
Since its discovery, Jigsaw has been involved in several campaigns targeting individuals and small businesses. These campaigns typically involve mass distribution of phishing emails designed to reach a wide audience. The use of popular themes or current events in these emails increases the likelihood of recipients opening them. While Jigsaw has not been associated with any major high-profile attacks, its psychological tactics and destructive nature have made it a persistent threat.
Detection and mitigation
Detecting Jigsaw involves monitoring for unusual file encryption activity and the presence of its characteristic ransom note. Security software can help identify and block the ransomware before it executes. Regularly updating software and operating systems can also reduce the risk of infection by closing vulnerabilities that ransomware might exploit.
Mitigation strategies include maintaining regular backups of important data, which can be restored in the event of an infection. Educating users about the dangers of phishing emails and safe browsing practices can further reduce the risk of ransomware attacks. In the event of a Jigsaw infection, it is crucial to avoid paying the ransom, as this does not guarantee file recovery and may encourage further criminal activity.