The threat actor is impersonating Microsoft in an attempt to exploit their user base for monetary gain. Talos found a spam campaign that was taking advantage of a different type of current event. The payload is CTB-Locker, a ransomware variant. Using Tor and Bitcoin they are able to remain anonymous and quickly profit from their malware campaigns with minimal risk. The malware is using asymmetric encryption that allows the adversaries to encrypt the user’s files without having the decryption key reside on the infected system.”]
Source: https://blog.talosintelligence.com/2015/07/your-files-are-encrypted-with-10-upgrade.html