Hacking malicious botnets, such as the Locky Ransomware, and then replacing their payloads with warning content for the user has become the norm, with another such incident reported by the F-Secure team.
The company says that one of its security researchers came across a strange sample originating from the server network (botnet) from which most of the spam- is sent out.
The file was a ZIP archive containing a JavaScript file. If the user double-clicks on this JavaScript, the script will normally download the Locky ransomware and launch it, effectively encrypting their files.
This time, F-Secure researcher Päivi T discovered that, instead of Locky, this file was downloading something different, which also activated it.
It appears that someone had hacked the Locky distribution network, replaced the ransomware payload with a benign file that displayed a simple pop-up to users warning them not to open email attachments from untrusted sources.

Something similar happened last February, when someone hacked the Dridex botnet to deliver a version of the Avira antivirus installer instead of the Dridex banking trojan, and then again last month with the Locky network, when someone replaced the ransomware with an empty file that read “Stupid Locky.”
