The group is abusing trusted remote management and file transfer tools to deliver a Linux encryptor on Windows machines.