JCry

S0389

Malware.View on attack.mitre.org

About this malware

JCry is ransomware written in Go. It was identified as apart of the #OpJerusalem 2019 campaign.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1059.001
PowerShell

JCry has used PowerShell to execute payloads.

T1059.003
Windows Command Shell

JCry has used cmd.exe to launch PowerShell.

T1059.005
Visual Basic

JCry has used VBS scripts.

T1204.002
Malicious File

JCry has achieved execution by luring users to click on a file that appeared to be an Adobe Flash Player update installer.

T1486
Data Encrypted for Impact

JCry has encrypted files and demanded Bitcoin to decrypt those files.

T1490
Inhibit System Recovery

JCry has been observed deleting shadow copies to ensure that data cannot be restored easily.

T1547.001
Registry Run Keys / Startup Folder

JCry has created payloads in the Startup directory to maintain persistence.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Carbon Black JCry May 2019 Open source
    Lee, S.. (2019, May 14). JCry Ransomware. Retrieved June 18, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.