Everyone now knows and has read about the OpenSSL Heartbleed, a critical error in the OpenSSL runtime that allows attackers to read portions of the affected server's memory, exposing user data.

The Heartbleed vulnerability made front-page news worldwide, but some readers still do not know its nature, otherwise they wouldn't have been victims of the spam that followed.
Spammers take every opportunity and this time they exploit the infamous Heartbleed bug to scare users and lead them to install an Anti-Heartbleed software on their systems, which of course is malware.
The researchers at Symantec uncovered a spam campaign that spreads by sending messages and warn unsuspecting users that their system can still be “infected” by the Heartbleed bug (!). Thus they ask them to run the Heartbleed bug removal tool (which comes attached to the message) in order to remove the virus from their system.

Those who do not know that Heartbleed is not a virus or malware, but a vulnerability of OpenSSL fall into the spammers' trap.
If someone opens the attachment that appears to be a docx file, an encrypted zip file will also arrive. When the victim extracts the contents of the zip file, they will find an executable .Exe that they think is the tool for removing the Heartbleed bug.

As soon as it runs the .exe it downloads a keylogger in the background, without his knowledge, while a progress bar appears with a message stating that the Heartbleed bug was not found and the computer is clean.

The victim feels relieved after learning that they are not at risk from Heartbleed, but at the same time they are unaware that there is a keylogger that records what they type on their computer. The keylogger that has been installed in the background, besides recording keystrokes, takes screenshots and sends the information to the criminals.
