DEADWOOD Wiper take place of the Apostle Wiper, which has many logical flaws and it did not work as expected by the attackers named as Agrius. Agrius also utilized DEADWOOD (aka Detbosit), a wiper. It is written in C++ using the Boost libraries.
Apostle is a .NET based malware that evolves from a Wiper to full-featured ransomware. It shares code with another tool from Agris APT arsenal, IPsec Helper.
IPsec Helper is a backdoor implant used by Agrius APT. Agrius is attributed to Iran and allegedly targets Israeli systems. IPsec Helper is written in .net and provides many services to its owner.
XFSCashNCR ATM Malware is found to be targeting Chile's NCR ATMs. There no packing or encrypting in malware which suggest that it is in development stage also it Supports multi-currency but requires input...
Zeppelin Ransomware is successor of VegaLocker and is written in Delphi. Zeppelin is a highly configurable malware and can be deployed as an EXE, DLL, or wrapped in a PowerShell loader.