Security researchers observed a new attack campaign in which the Viro botnet infects devices with ransomware and then uses those compromised machines to infect more victims. The attack displays a ransom note in French after successfully encrypting files using RSA encryption. The researchers speculated that Viro may be based on a variant of Locky, which made headlines throughout 2017. Viro’s C&C server has been taken down since they first observed the attacks meaning it will no longer be able to encrypt files even if it lands on a victims machine.”]