French authorities warned that a large unsolicited email campaign used the subject line "Nous avons reçu votre paiement." to lure recipients into downloading a fake invoice, leading to ransomware infections across Windows environments. The messages linked to malicious downloads that ultimately delivered nested ZIP archives and executables, after which the malware encrypted files on infected workstations and accessible network shares before demanding payment for decryption.
Analysis of the campaign tied the activity to PyLocky, a Python-based ransomware family that impersonated Locky in its ransom note but was technically unrelated to the original Locky malware. Researchers said the operation heavily targeted European victims, especially in France, and used signed executables, PyInstaller, and Inno Setup to hinder analysis; the malware encrypted numerous file types with 3DES, gathered host details through WMI, delayed execution on low-memory systems as an anti-sandbox measure, and sent victim information to a command-and-control server over HTTP.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos released a free decryption tool for PyLocky ransomware victims. Talos said the tool works only when the infected machine's initial command-and-control traffic was captured, because data from that exchange is required for file recovery.
On August 2, 2018, a spam run distributed PyLocky to French businesses using invoice-themed social engineering lures. One observed message used the French subject line "Nous avons reçu votre paiement" and directed users to a malicious download URL.
CERT-FR reported a new unsolicited email campaign in France beginning in late July 2018 that distributed ransomware identified as Locky Locker. The phishing emails used the subject line "Nous avons reçu votre paiement" and linked victims to a ZIP-in-ZIP archive containing an executable.
Trend Micro observed waves of spam email campaigns distributing the Python-based PyLocky ransomware in late July 2018 and throughout August 2018. The activity appeared concentrated in European countries, particularly France, and used invoice-themed lures.
CERT-FR issued an alert describing the ransomware spam campaign affecting Windows systems in France and warning that anti-spam gateway blocking rates were relatively low. The alert included malicious URLs tied to the campaign and recommended containment, blocking, mailbox cleanup, and system rebuild actions.
Trend Micro published an analysis explaining that PyLocky only impersonated Locky in its ransom note and was actually an unrelated Python-based ransomware family. The report detailed its packaging with PyInstaller and Inno Setup, anti-sandbox behavior, 3DES encryption, command-and-control communications, and associated indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcecert.ssi.gouv.fr
Open sourceblog.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.