Many different threat actors are using this crypting service/tool for their operations, possibly buying it from the developer itself.
Source: Threadpost