A recent sample of this campaign was shared with BleepingComputer by security researcher Yves Agostini. These spam emails have a subject of “Invoice Due”” and pretend to be about outstanding balances. When these invoices are opened they install the AZORult information stealing Trojan and the Hermes 2.1 Ransomware onto the recipient’s computer. This particular ransomware does not change the filenames
Source:

