A new ransomware called VCrypt is targeting French victims by utilizing the legitimate 7zip command-line program to create password-protected archives of data folders.
BleepingComputer was told today about a new ransomware that was deleting all of a victim's files found in Windows data folders and then creating new "encrypted" files named after the folder name.
These encrypted files would utilize a naming format of username_foldername.vxcrypt.
For example, the files in the Documents folder would be deleted, and a file named User_documents.vcrypt would be created, as shown in the image below.