Skip to content

Jigsaw

Jigsaw is a Windows ransomware family first seen in 2016 and initially referred to as BitcoinBlackmailer.

Profile source: Mallory opens in a new tab

Jigsaw

Family profile

Jigsaw is a Windows ransomware family first seen in 2016 and initially referred to as BitcoinBlackmailer. It became widely known for using imagery and language derived from the Saw film franchise, including Billy the Puppet, to intimidate victims and pressure rapid payment. The malware encrypts files, commonly appends the .fun extension, and presents a ransom interface that threatens escalating consequences over time, including progressive deletion of encrypted files, higher ransom demands, and eventual destruction of all affected data if payment is not made. Some variants also punish system restarts by deleting large numbers of files.

Jigsaw is implemented in .NET and has been observed copying itself into the user profile application-data area and displaying a dedicated blackmail window after encryption. The ransom interface can include options to list encrypted files and to request decryption, with some samples attempting to contact remote infrastructure to obtain or validate a decryption key. The family is notable for psychological extortion tactics rather than technical sophistication, using countdown timers, taunting messages, and themed visual elements to increase victim distress.

Observed delivery has included malicious downloads from file-hosting services and pornography-themed lures, and reporting has also associated ransomware infection risk with suspicious email attachments such as JavaScript files and macro-enabled documents in the broader context of Jigsaw activity. Jigsaw has also been discussed alongside other ransomware families because of superficially similar file-deletion behavior, but such links are weak and not sufficient to establish common authorship.

Jigsaw is also notable for poor cryptographic implementation in at least some analyzed samples. Researchers found that the encryption key was hardcoded in the binary, enabling file recovery through reverse engineering without paying the ransom. This design weakness, together with other implementation flaws, led to public decryptors becoming available and reduced the family’s effectiveness compared with more mature ransomware operations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
3 IP / 2 hostnames

Leading locations

  • CA1
  • CN1
  • IE1
  • NL1
  • US1

Leading providers

  • Amazon.com, Inc.2
  • Hangzhou Alibaba Advertising Co.,Ltd.1
  • HosterDaddy Private Limited1
  • Omegatech LTD1

Infrastructure traits

  • Hosting 5

Samples

Recent associated samples

MITRE ATT&CK

Jigsaw in ATT&CK

10 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.