A cryptor program dubbed Polyglot emerged in late August. It is distributed in spam emails that contain a link to a malicious RAR archive. When the infected file is launched, nothing appears to happen. However, the cryptor copies itself under random names and writes itself to a dozen or so places. When installation is complete, file encryption starts. The users files do not appear to change (their names remain the same), but the user is no longer able to open them. The cryptor contacts its C&C, which is located on the Tor network, for the ransom sum and the bitcoin address.”]
Source: https://securelist.com/polyglot-the-fake-ctb-locker/76182/