FTCode

First seen
2019-10-01 00:00:00
Malware type
ransomware, loader
Profile updated
2026-07-07 13:45:55

Targeted industries: financial-services

Targeted regions: country_code:it

Context

A targeted email campaign has been spotted distributing the JasperLoader to victims. While the JasperLoader was originally used to then install Gootkit, Certego has observed it now being used to infect victims with a new ransomware dubbed FTCODE. Using an invoice-themed email appearing to target Italian users, the attackers attempt to convince users to allow macros in a Word document. The macro is used to run PowerShell to retrieve additional PowerShell code.

Reports & references

  • certego.net — Malware Tales Ftcode (report)
  • exchange.xforce.ibmcloud.com — Ftcode Ransomware 45Dacdc2D5Cf30722Ced20B9D37988C2 (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Ftcode (report)
  • ransomlook.io — Ftcode (report)
  • dissectingmalwa.re — Nicht So Goot Breaking Down Gootkit And Jasper Ftcode (report)
  • certego.net — Ftdecryptor A Simple Password Based Ftcode Decryptor (report)
  • github.com — Analysis.Md (report)
  • kpn.com — Ftcode Taking Over A Portion Of The Botnet (report)
  • zscaler.com — Ftcode Ransomware New Version Includes Stealing Capabilities (report)
  • isc.sans.edu — 29122 (report)
  • nakedsecurity.sophos.com — Russian Ransomware Windows Powershell (report)
  • blog.rootshell.be — Simple Dga Spotted In A Malicious Powershell (report)

External references