The #OpJerusalem2019 campaign is the new cyberattack via the Jcry ransomware that attacks Windows users by encrypting their files and demanding a ransom!

The #OpJerusalem2019 campaign began with a cyberattack against the Israeli government and private websites, such as Coca-Cola, ToysRUs, McDonald's.
An anonymous group of hackers has hacked hundreds of websites and defaced nearly 1 million Israeli websites belonging to some of the top brands.
The attackers' goal was to "erase Israel from the Internet" in protest of the Israeli government's behavior in the Israeli-Palestinian conflict.
There are various attack vectors used by cybercriminals, including website defacements, distributed denial-of-service attacks (DDoS) , and the exploitation of vulnerabilities in third-party plug-ins.
The #OpJerusalem attack users Windows by infecting them with the JCry ransomware which is distributed via defaced websites.
A security flaw in the nagich.co.il pluginloaded code JavaScript that compromised websites and allowed attackers to exploit and compromise website data.
Once hackers manage to compromise the websites, they send the malicious javascript which in turn triggers the following malicious Adobe update message which asks users to click on “update”.

Clicking it immediately activates the malicious file “flashplayer_install.exe” from hxxp://185.163.47.134.

The first .execontains 3 archives, one of which is responsible for encrypting the user's files.
After successful encryption , the new file extension (. jcry ) is added

Finally, the ransomware will be created and displayed as JCRY_Note.html. The hacker demands a payment of $500 in bitcoin.

To pay the ransom and decrypt the files, the hackers provide a recovery link that redirects to Tor where the wallet address and the unique decryption key are located.
By obtaining the key, users recover their files.

