logo

FTCODE Ransomware: New Version can Steal Data

ID: 6c46aff6-4d95-5905-a193-5517cbab4d1c

STIX ID: report--6c46aff6-4d95-5905-a193-5517cbab4d1c

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ documents the FTCODE ransomware campaign (versions ~1001.7–1117.1) that uses malicious Office macros and VBScript to download a PowerShell payload, tricks users with a decoy image, establishes persistence via a startup shortcut and scheduled task, encrypts files using Rijndael while appending a GUID-derived extension, and exfiltrates stored credentials from multiple browsers and Outlook; the report includes detailed technical indicators (MD5s and URLs), C2 interaction patterns, and stealer/encryption implementation details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.