It could be worse than just "we will make you pay for a free software developped by someone else" maybe…
Do you think it could be related to the same sort of attack than against keepass ?
https://www.bleepingcomputer.com/news/security/fake-keepass-password-manager-leads-to-esxi-ransomware-attack/