PyLocky is a Python-based ransomware family that masquerades as Locky in its ransom messaging but is unrelated to the Locky malware family. It was observed in 2018 in spam-driven campaigns, particularly affecting organizations and users in Europe, with notable concentration in France. Reported victims included small and medium-sized businesses, larger enterprises, associations, and home users.
PyLocky is commonly delivered through invoice-themed spam lures that direct recipients to download an archive containing a Windows executable. The malware has been packaged with PyInstaller and distributed with Inno Setup components, complicating static analysis and detection. After execution, it drops Python runtime components and supporting libraries, gathers host information through Windows Management Instrumentation, and performs anti-analysis checks based on system memory before proceeding.
The ransomware enumerates files across logical drives and encrypts a broad range of file types. Reported analyses indicate it uses the PyCrypto library and 3DES for file encryption, generates victim-specific values including a random user identifier, password, and initialization vector, and communicates with command-and-control infrastructure to transmit system information used in the encryption workflow. Encrypted files have been observed with extensions including lockedfile, lockymap, and locky depending on version. PyLocky then drops ransom notes, including multilingual variants, to instruct victims on payment and recovery.
PyLocky demonstrates defense-evasion characteristics through packaging and anti-sandbox delays, and it includes host reconnaissance prior to encryption. Public decryptors have been released for versions 1 and 2 through law-enforcement and researcher collaboration, enabling recovery in some cases without paying the ransom. Separate research also documented a decryptor workflow that depended on capturing the malware’s initial command-and-control traffic because data exchanged during early communications was incorporated into the encryption process.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
When PyLocky executes, it generates a random user ID and password and gathers information about the infected machine using WMI wrappers.
When PyLocky executes, it generates a random user ID and password and gathers information about the infected machine using WMI wrappers.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that targets French and European companies, increases ransom over time, and uses WMI for system information gathering. Decryption requires capturing initial C2 network traffic.
Ransomware active in Europe that encrypts files and appends extensions including .lockedfile, .lockymap, and .locky. It uses Tor-based command-and-control servers referenced in ransom notes. The released decryptor for versions 1 and 2 appears to rely on two hard-coded private RSA keys, suggesting investigators may have obtained the master private keys from attacker infrastructure rather than exploiting a cryptographic flaw.
Python-based ransomware that encrypts files on victim machines, appends the .lockedfile extension, communicates with a C2 server during initial execution to send system information and encryption-related data, and overwrites original files with a ransom note.
Python-based ransomware packaged with PyInstaller that encrypts a hardcoded list of file types using 3DES via the PyCrypto library, drops multilingual ransom notes, performs anti-sandbox checks using WMI and long sleep delays, and sends victim system information to a C&C server via POST after encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.