Even though Jakub Kroustek posted his findings about the @foxmail ransom on October 19, at the time of us writing about the strain we uncovered (November 7), only 44 out of 67 antivirus engines detect the malicious file he uncovered, as you can see on VirusTotal.
Our own investigation began with a malicious exe dropped through a .NET file and another associated HTA file, which, once unpacked, directs the victim to pay a Bitcoin ransom to the backto...@foxmail.com email address.
In regards to the TLS 1.2+, currently the above platforms should already support and be using TLS1.2+ - Outlook 2013 fully patched has support and we are using SSL only for incoming / outgoing for GSuite imap.
aa06259810