According to Heimdal Security’s Andra Zaharia, this campaign is also executed with the help of an exploit kit. “The campaign is carried out by installing a cocktail of malware on the compromised PC.
Link: A deadly campaign delivers Pony info-stealer followed by Cryptowall ransomware