FTCODE Ransomware: New Version can Steal Data
ID: 6c46aff6-4d95-5905-a193-5517cbab4d1c
STIX ID: report--6c46aff6-4d95-5905-a193-5517cbab4d1c
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ documents the FTCODE ransomware campaign (versions ~1001.7–1117.1) that uses malicious Office macros and VBScript to download a PowerShell payload, tricks users with a decoy image, establishes persistence via a startup shortcut and scheduled task, encrypts files using Rijndael while appending a GUID-derived extension, and exfiltrates stored credentials from multiple browsers and Outlook; the report includes detailed technical indicators (MD5s and URLs), C2 interaction patterns, and stealer/encryption implementation details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
