Ransomware strain FTCODE has been active since at least 2013. FTCODE can now steal credentials and passwords from web browsers and email clients. The malware has the ability to encrypt a wide variety of files, including “.doc,” “.sql,” “*.xls” and several others. The FTCODE ransom note typically demands an initial ransom of $500, but the price steadily goes up the longer the victims don’t pay it. The ransom demands range from $500 to $1,000.”]
Source: https://www.govinfosecurity.com/updated-ftcode-ransomware-now-steals-credentials-passwords-a-13638