Description Summary
Locky was one of 2016's most widespread ransomware families, distributed at massive scale through the Necurs botnet via spam emails carrying malicious Microsoft Office macro documents (and later JavaScript). It is linked to the Dridex/Evil Corp actor set and cycled through many encrypted-file extensions across its versions.
Threat Actor
Linked to the Dridex/Evil Corp operators; distributed via the Necurs botnet.
Technical Indicators
Encryption Extension
.locky / .zepto / .odin / .aesir / .osiris / .diablo6 / .thor
Encryption Algorithm
AES-128 (files) + RSA-2048 (key wrapping)
Ransom Note Name
_Locky_recover_instructions.txt / .bmp (desktop wallpaper)
Targeted Industries
Cross-sector (healthcare notably hit)
First Seen
February 2016
Last Seen
~2017
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 1 | T1566.001 | Spearphishing Attachment |
| Execution x 2 | T1204.002 | User Execution: Malicious File |
| T1059.005 | Command and Scripting Interpreter: Visual Basic (macros) | |
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery |