HomeSecurityFTCode PowerShell Ransomware reappears in new spam campaign

FTCode PowerShell Ransomware Resurfaces in New Spam Campaign

FTCode Researchers have discovered a new spam campaign targeting Italian users and using an old PowerShell ransomware. For the past few days, there has been talk of a new ransomware called FTCode, which was distributed via spam emails.

However, according to Certego, FTCode is identical to the software discovered by Sophos in 2013.

“The name may seem new, but the first appearance of this threat was in 2013 and was discovered by Sophos. Then, for about 6 years, nothing was observed.”.

Certego researchers believe ransomware may not have been as successful in 2013 because PowerShell programs weren't as popular as they are today, so hackers had to resort to other types of malware .

Distribution of FTCode via spam campaign

Researchers discovered that the ransomware was spreading via spam emails containing malicious files Word. It targeted Italian users.

According to researcher JamesWT, the malicious files were of varying content. Sometimes they appeared as invoices, sometimes as other documents, and sometimes as a job application.

An example of such an email is the following:

FTCode

If users open the attachment, they will see a Word document that requests content activation in order to continue the process.

FTCode PowerShell Ransomware Resurfaces in New Spam Campaign

If activated, the process proceeds as follows: malicious macros are launched that execute a PowerShell command. This downloads and installs the JasperLoader malware downloader and then encrypts the computer.

FTCode

Researchers found that the first malware used is the JasperLoader downloader. This is used to download and install other malicious programs.

The malicious script will then execute various commands to backups Windows.

After these procedures are done, the script begins encrypting the victim's files.

FTCode PowerShell Ransomware Resurfaces in New Spam Campaign

After encryption, victims will see the .FTCODE on the encrypted files.

FTCode PowerShell Ransomware Resurfaces in New Spam Campaign

Then, the ransomware administrators add a note (READ_ME_NOW.htm) to each folder, through which they demand a ransom.

The note below contains a link to a site Tor payment, which contains instructions on how to purchase a file decryption tool, which costs $500 USD.

FTCode PowerShell Ransomware Resurfaces in New Spam Campaign

If victims visit the payment site, they will receive a bitcoin and the amount they must pay to recover their files.

FTCode

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS