Locky Ransomware

Description Summary

Locky was one of 2016's most widespread ransomware families, distributed at massive scale through the Necurs botnet via spam emails carrying malicious Microsoft Office macro documents (and later JavaScript). It is linked to the Dridex/Evil Corp actor set and cycled through many encrypted-file extensions across its versions.

Threat Actor

Linked to the Dridex/Evil Corp operators; distributed via the Necurs botnet.

Technical Indicators

Encryption Extension
.locky / .zepto / .odin / .aesir / .osiris / .diablo6 / .thor
Encryption Algorithm
AES-128 (files) + RSA-2048 (key wrapping)
Ransom Note Name
_Locky_recover_instructions.txt / .bmp (desktop wallpaper)
Targeted Industries
Cross-sector (healthcare notably hit)
First Seen
February 2016
Last Seen
~2017
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 1 T1566.001 Spearphishing Attachment
Execution x 2 T1204.002 User Execution: Malicious File
T1059.005 Command and Scripting Interpreter: Visual Basic (macros)
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery