FTCODE Ransomware encrypts user data using AES-256 (in CBC mode) + RSA-1024, and then requires a ransom of $500 to return the files. FTCODE ransomware mainly target Italian companies. It is spreading via email spam campaign which previously know to distribute JasperLoader and Gootkit.
Emissary Panda, which also goes by other identikits such as APT27, IronTiger, BronzeUnion, TG-3390, and LuckyMouse , is a decade old Chinese APT. It primarily targets aerospace, government, defense, technology, energy, and manufacturing sectors. Not much is know about the activities of this group.
cURL is generally know for accessing and downloading web pages or files form command line. However, there is another great feature that utilize cURL to test connectivity or access other TCP services running on other ports. A sample syntax for the command is as follows
InnfiRAT remote access Trojan is written in .net. It primarily steals his victim's information such as browser cookies, crypto currency wallet details, session data.
TFlower Ransomware is being installed in a corporate network through exposed Remote Desktop services that are being hacked by attackers.