Researchers have discovered a new spam campaign targeting Italian users and using an old PowerShell ransomware. For the past few days, there has been talk of a new ransomware called FTCode, which was distributed via spam emails.
However, according to Certego, FTCode is identical to the software discovered by Sophos in 2013.
“The name may seem new, but the first appearance of this threat was in 2013 and was discovered by Sophos. Then, for about 6 years, nothing was observed.”.
Certego researchers believe ransomware may not have been as successful in 2013 because PowerShell programs weren't as popular as they are today, so hackers had to resort to other types of malware .
Distribution of FTCode via spam campaign
Researchers discovered that the ransomware was spreading via spam emails containing malicious files Word. It targeted Italian users.
According to researcher JamesWT, the malicious files were of varying content. Sometimes they appeared as invoices, sometimes as other documents, and sometimes as a job application.
An example of such an email is the following:

If users open the attachment, they will see a Word document that requests content activation in order to continue the process.

If activated, the process proceeds as follows: malicious macros are launched that execute a PowerShell command. This downloads and installs the JasperLoader malware downloader and then encrypts the computer.

Researchers found that the first malware used is the JasperLoader downloader. This is used to download and install other malicious programs.
The malicious script will then execute various commands to backups Windows.
After these procedures are done, the script begins encrypting the victim's files.

After encryption, victims will see the .FTCODE on the encrypted files.

Then, the ransomware administrators add a note (READ_ME_NOW.htm) to each folder, through which they demand a ransom.
The note below contains a link to a site Tor payment, which contains instructions on how to purchase a file decryption tool, which costs $500 USD.

If victims visit the payment site, they will receive a bitcoin and the amount they must pay to recover their files.

