The zip attachment of the "PURCHASE ORDER" email contains a bat file. This runs a PS, which infects the machine with malware. The stolen data is exfiltrated via SMTP.
Cybercrime, AstraLocker and Yashma victims now have a free decryptor

AstraLocker and Yashma victims now have a free decryptor, Emsisoft cybersecurity experts released a free decryptor that can be downloaded from the company’s servers
AstraLocker and Yashma victims now have a free decryptor, thanks to Emsisoft cybersecurity experts. The tool can be downloaded from the company’s servers, and allows the user to recover encrypted files, using easy-to-follow instructions available in this usage guide. AstraLocker recently announced the closure of its ransomware operations and the cybercrime gang submitted a ZIP archive with the decryptors to VirusTotal. No official reason has been submitted. Researchers, however, believe it could be linked to the fact that the spotlight has recently turned on the group and, as a result, there could be problems with the police force. Yashma is the new version of Chaos malware.