Locky is a Windows ransomware family that emerged in 2016 and became one of the most prominent large-scale malspam-delivered crypto-extortion threats of its period. It is closely associated with high-volume spam operations delivered through infrastructure such as the Necurs botnet and has been linked in multiple public reports to financially motivated activity clusters including TA505 and, more speculatively, Evil Corp. Locky was commonly distributed through phishing emails carrying malicious attachments such as macro-enabled Office documents, JavaScript downloaders in compressed archives, and other socially engineered file types. In some campaigns, Locky was delivered directly; in others it was fetched by intermediate downloaders such as QtLoader or by botnet-delivered loaders shared with Dridex operations.
Once executed, Locky encrypts victim files and presents ransom instructions, typically after contacting attacker infrastructure as part of its execution flow. Public reporting also documents anti-analysis and anti-debugging measures in some variants, as well as use of a domain generation algorithm for command-and-control resilience. Locky spawned multiple notable variants and closely related strains, including Zepto and Osiris, with Zepto widely assessed as an evolutionary extension of Locky sharing most of its code base and core encryption logic.
Locky campaigns relied heavily on social engineering themes such as invoices, receipts, order confirmations, and business documents, and were sent at very large scale across many sectors and geographies. The malware was observed affecting enterprises, public institutions, and healthcare organizations, including hospital-focused incidents. Locky also figured prominently in the broader evolution of cybercriminal operations that shifted from banking trojans toward ransomware monetization, and it remains a historically significant example of industrialized spam-driven ransomware distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Similar to techniques utilized by Dridex and Locky in mid-2017, the PDF contained an embedded RTF file which contains an embedded remote object that attacks CVE-2017-8579.
CVE-2015-1701 Classification: 1-Day Basic Description: CreateWindow callback validation error Used by the following malware families: Locky | CVE-2015-1701 ... Used by the following malware families: Locky.
CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Locky ransomware operates using the same delivery method for the downloader, with similar subject lines and attachments. Attackers also use the same botnets to deliver both Dridex and Locky ransomware, sometimes simultaneously.
Locky ransomware operates using the same delivery method for the downloader, with similar subject lines and attachments. Attackers also use the same botnets to deliver both Dridex and Locky ransomware, sometimes simultaneously.
A cybercriminal gang have been arrested for spreading the Locky ransomware among hospitals... They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail...”
If this check failed, Locky would be served instead... Thus, we expect to see a different download location and likely a Locky payload.
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Ces pièces jointes pouvaient notamment être des archives zip ou 7zip contenant des scripts VBS ou Javascript à faire exécuter par ses victimes.
Ces pièces jointes pouvaient notamment être des archives zip ou 7zip contenant des scripts VBS ou Javascript... Ce dernier redirige la victime vers une URL d’un site légitime mais compromis.
It therefore distributed bugged Office documents via the DDE mechanism less than a month after the potential abuse of this feature became common knowledge.
Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process.
Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process.
HOOK INJECTION VIA SETWINDOWSHOOKEX... Malware can leverage hooking functionality to have their malicious DLL loaded upon an event getting triggered in a specific thread.
108 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
94 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example ransomware family in a citation related to backup monitoring and ransomware risk; the content does not analyze Locky itself.
A ransomware family mentioned as one of the payloads delivered by Magnitude Exploit Kit.
Legacy ransomware family referenced only for historical comparison: a 2016 'Osiris' variant was based on Locky; the newly reported Osiris strain is stated to be unrelated.
Legacy ransomware family referenced only to clarify that the newly reported Osiris is not related to the 2016 Osiris/Locky iteration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.