Locky is a ransomware family first released in 2016 and widely distributed through large-scale spam and phishing campaigns. The content consistently describes delivery via malicious email attachments, especially macro-enabled Word or Excel documents, DOC/DOCM files, ZIP/RAR archives containing JavaScript, and invoice- or billing-themed lures; some reporting also notes delivery through exploit kits such as Magnitude EK. Multiple sources state that the same delivery infrastructure and botnets used for Dridex were also used for Locky, including Necurs, and that actors behind major Dridex campaigns were involved in Locky distribution. TA505/Hive0065 is repeatedly associated with Locky campaigns, including large malspam operations and later COVID-19-themed phishing in 2020.
On execution, Locky encrypts victim files, including files on local, removable, and network drives, and renames them. The content specifically notes the format {unique ID per victim}{identifier}.locky and also describes random 16-character filenames with extensions used across variants including .locky, .zepto, .odin, .thor, .aesir, .zzzzz, and .osiris. After encryption, victims are instructed to use Tor to access a payment site and pay a ransom, commonly cited as roughly 0.5 to 1 bitcoin. The malware is described as using RSA-2048 and AES-128 encryption, with server-side key generation, and no decrypter is noted in the cited reporting for the relevant variants.
The content highlights Locky as one of the early ransomware families that helped commercialize large-scale data extortion in 2016. It was sent at very high volume, including campaigns of tens of millions of messages and, in 2017, as many as one million messages per day before operations stopped. Delivery chains included intermediate loaders such as RockLoader, which was observed downloading Locky as well as other malware. Reporting also notes evasion and anti-analysis changes over time, including heavily obfuscated JavaScript downloaders, malformed content types, misleading archive/file extensions, junk files in archives, and a June 2016 loader update with VM-detection and code-relocation techniques.
Locky is closely linked in the content to the Dridex ecosystem; early versions are described as believed to have been created by the operators behind Dridex/Cridex, and the same botnets, subject lines, attachments, and downloader methods were used for both malware families, sometimes simultaneously. Industry and government reporting cited in the content attributes Dridex-, BitPaymer-, and Locky-related malspam activity to actors referred to as TA505 or Evil Corp, though the content most consistently and directly associates Locky with TA505.
Targeting in the content is broad but includes notable impact on healthcare and education. Healthcare is specifically described as attractive to ransomware operators, and Locky is cited in that context as an example of profit-driven targeting. Reported incidents include Hollywood Presbyterian Medical Center paying a ransom after infection via an email attachment disguised as a Microsoft Word invoice, and infections at UK schools. Mentioned indicators and artifacts include encrypted files ending in .locky or later variant extensions such as .osiris, ransom-note files such as OSIRIS-[random].htm for the Osiris variant, and sample hashes including 2e4319ff62c03a539b2b2f71768a0cfc0adcaedbcca69dbf235081fe2816248b, ed2f09e648dca8f0ca75466b1442f6e599afddc80777e0559fb6881c6cd9ff3, b60fde281d91cc3e7ea3e343ee5b13a31def564903c0136ae928f70e25c3c02, afc78b5630726c907a69d62a6c8a7d86326e21383fe3aae1efc715342238e02, and bc98c8b22461a2c2631b2feec399208fdc4ecd1cd2229066c2f385caa958daa3.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor... CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet Explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Microsoft released a patch and encouraged users to disable jscript.dll.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the messages and the delivery suggest they were sent by threat actor TA505, known for sending large-scale Dridex, Locky, and GlobeImposter campaigns, among others, over the last four years.
Locky ransomware operates using the same delivery method for the downloader, with similar subject lines and attachments. Attackers also use the same botnets to deliver both Dridex and Locky ransomware, sometimes simultaneously.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
In recent weeks, we detected a marked increase in email campaigns attempting to install Locky... This particular campaign... used malicious document attachments... Outside of the very large campaign detected on April 7th, the ransomware in many of these campaigns is being installed via JavaScript attachment files rather than documents.
the spreading mechanism via macros in Word or Excel documents sent out via carefully crafted spear-phishing emails is exactly the same for both of these strains.
JavaScript attachments have been popular with attackers for a while now. The attachments are typically heavily obfuscated; they download and run additional malicious payloads.
A trojan is embedded in the document, and once opened, it executes its payload.
Phishing messages... persuade victims to activate open attachments... By default, software generally prevents execution of macros without user permission. Attached files... contain instructions on how a user should enable content and specifically macros, effectively using social engineering to facilitate the download.
In addition to the use of Rockloader, threat actors distributing Locky have been using an array of obfuscation techniques... Increasingly convoluted JavaScript obfuscation... The specific JavaScript that downloads Locky uses obfuscation techniques including character substitution, string concatenation, dead code, integer to character conversion, and other tricks.
On March 29th, the actor attempted to send Zip attachments with improper file extensions “docx”, “gif”, ”jpg”, “pdf”, “rar”, and “tiff”... On March 30th, an actor also attempted to use attachments with double file extensions, including JPEG.zip, doc.zip, pdf.zip, and others.
Spamhaus researchers issued listings for over 7,000 botnet Command & Control ("C&C") servers... These C&C servers enabled and controlled online crime such as credential theft, e-banking fraud, spam and DDoS attacks. They were also used for the retrieval of stolen data.
This actor is frequently using it as an intermediate “downloader”. This downloader has been distributed both through JavaScript attachments and malicious documents and, in turn, downloads Locky... on April 6th and 7th, 2016, we spotted this downloader being used to load other malware including Dridex 220, Pony, and Kegotip.
Once downloaded and active, Dridex has a wide range of capabilities, from downloading additional software to establishing a virtual network to deletion of files.
While WannaCry might be seen as a failed operation from a financial perspective for the attackers ... the epidemic has raised the profile of ransomware; both to the general public and likely for the cybercriminal fraternity as well. Ransomware has already experienced great success ... because it simply works. People will pay ransom demands to get their encrypted files back.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family mentioned as one of the payloads delivered by Magnitude Exploit Kit.
Legacy ransomware family referenced only for historical comparison: a 2016 'Osiris' variant was based on Locky; the newly reported Osiris strain is stated to be unrelated.
Legacy ransomware family referenced only to clarify that the newly reported Osiris is not related to the 2016 Osiris/Locky iteration.
Ransomware that encrypts files and demands payment for decryption; known for widespread distribution via email attachments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.