Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 2 hostnames
Jigsaw is a Windows ransomware family first seen in 2016 and initially referred to as BitcoinBlackmailer.
Profile source: Mallory opens in a new tabJigsaw
Jigsaw is a Windows ransomware family first seen in 2016 and initially referred to as BitcoinBlackmailer. It became widely known for using imagery and language derived from the Saw film franchise, including Billy the Puppet, to intimidate victims and pressure rapid payment. The malware encrypts files, commonly appends the .fun extension, and presents a ransom interface that threatens escalating consequences over time, including progressive deletion of encrypted files, higher ransom demands, and eventual destruction of all affected data if payment is not made. Some variants also punish system restarts by deleting large numbers of files.
Jigsaw is implemented in .NET and has been observed copying itself into the user profile application-data area and displaying a dedicated blackmail window after encryption. The ransom interface can include options to list encrypted files and to request decryption, with some samples attempting to contact remote infrastructure to obtain or validate a decryption key. The family is notable for psychological extortion tactics rather than technical sophistication, using countdown timers, taunting messages, and themed visual elements to increase victim distress.
Observed delivery has included malicious downloads from file-hosting services and pornography-themed lures, and reporting has also associated ransomware infection risk with suspicious email attachments such as JavaScript files and macro-enabled documents in the broader context of Jigsaw activity. Jigsaw has also been discussed alongside other ransomware families because of superficially similar file-deletion behavior, but such links are weak and not sufficient to establish common authorship.
Jigsaw is also notable for poor cryptographic implementation in at least some analyzed samples. Researchers found that the encryption key was hardcoded in the binary, enabling file recovery through reverse engineering without paying the ransom. This design weakness, together with other implementation flaws, led to public decryptors becoming available and reduced the family’s effectiveness compared with more mature ransomware operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 6ff59d49647c897e8c134519f5eb73ff53bd55386a24c55058e7427598d5a754 ecda70414eaa3354ef877c71c445d49294f142fc694e81f0002d385ff1060d02 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.