FTCode Ransomware
First observed in 2013, FTCode is a PowerShell-based ransomware tool targeting users in Western Europe.
Summary
First observed in 2013, FTCode is a PowerShell-based ransomware tool targeting users in Western Europe.
Affected platforms
The following platforms are known to be affected:
Threat details
FTCode is delivered as Office documents distributed through spam campaigns. When opened, several PowerShell commands within the documents are executed to install FTCode as well as either the JasperLoader or Gootkit backdoor malware.
Once installed, FTCode will create a scheduled task to maintain persistence before encryption all reachable files that match a hard-coded filetype list with an unidentified algorithm. It will then attempt to remove all Volume Shadow Copies and disable recovery services before displaying a ransom note.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 11 January 2022 1:33 pm