> Apart from encrypting the files and leaving ransom notes, the sample has none of the additional functionality that other threat actors tend to use in their Trojans: no C&C communication, no termination of running processes, no anti-analysis tricks, etc.
> Curiously, the ELF binary contains some debug information, including names of functions, global variables and source code files used by the malware developers.
Seems pretty amateurish...