FTcode ransomware targeted European organizations with phishing emails masquerading as company or court notifications and delivering oversized malicious archives intended to evade sandbox analysis. The infection chain used obfuscated VBScript droppers and attacker-controlled scripting to launch PowerShell, download additional payloads from .top domains, register victims with command-and-control infrastructure, and establish persistence through scheduled tasks before retrieving the ransomware payload.
A later FTcode variant expanded beyond encryption by stealing credentials from Chrome, Firefox, Thunderbird, Outlook, and Internet Explorer and exfiltrating them to the attacker. The malware stored victim identifiers locally, repeatedly polled its C2 servers, and in some cases delayed ransomware deployment for hours or days after the initial compromise, showing a shift toward a more flexible intrusion workflow built around scripting activity consistent with MITRE ATT&CK T1064.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Compared with the early January 2020 activity, the threat actor later updated FTcode to add credential dumping from Microsoft Outlook and Internet Explorer alongside its ransomware staging behavior.
The analysis states there was earlier FTcode activity in early January 2020, providing the baseline for later comparisons in the campaign's evolution.
A newer FTCODE version broadened its credential-stealing capability beyond Outlook and Internet Explorer to also target Mozilla Firefox, Mozilla Thunderbird, and Google Chrome. The report describes this as part of the malware's evolving data-theft functionality.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 56 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcegithub.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.