Locky is a Windows ransomware family that encrypts victim files and demands payment for decryption. It has been deployed by the financially motivated threat actor TA505 and distributed extensively through the Necurs spam botnet. Its distribution infrastructure and downloader-based infection methods overlap with campaigns delivering the Dridex banking trojan, and the two families have sometimes been distributed simultaneously. Zepto and Osiris are variants of Locky rather than separate malware families.
Locky spreads through large-scale phishing and malicious spam campaigns, commonly using business-themed messages impersonating invoices, payment receipts, or order confirmations. Delivery chains have included compressed archives containing JavaScript downloaders, nested archives containing executables, and malicious Microsoft Word documents. An October 2017 campaign abused Word Dynamic Data Exchange to launch a multistage infection chain involving QtLoader, which subsequently downloaded Locky. Exploit kits have also delivered Locky through software vulnerabilities, including Adobe Flash Player vulnerability CVE-2016-1019.
After execution, Locky searches for files to encrypt, renames encrypted files, and presents ransom instructions through documents, images, or desktop wallpaper changes. Observed variants direct victims to Tor-hosted payment services and demand Bitcoin. Locky attempts to delete Windows Volume Shadow Copies to obstruct recovery. Some variants remove their downloaded executable after encryption and employ anti-debugging and virtual-environment checks to hinder analysis. A flawed campaign variant failed on Windows 7 and later when Data Execution Prevention prevented its unpacker from executing; this limitation was specific to that deployment rather than the family as a whole.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Magnitude EK was found to be exploiting a previously unreported vulnerability in Adobe Flash, now assigned CVE-2016-1019. The exploit has been in the wild since at least March 31, 2016.
CVE-2012-1723 — Cerber, Locky; CVE-2016-1019 — Locky, Cerber.
Similar to techniques utilized by Dridex and Locky in mid-2017, the PDF contained an embedded RTF file which contains an embedded remote object that attacks CVE-2017-8579.
CVE-2015-1701 Classification: 1-Day Basic Description: CreateWindow callback validation error Used by the following malware families: Locky | CVE-2015-1701 ... Used by the following malware families: Locky.
CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment.
Attackers also use the same botnets to deliver both Dridex and Locky ransomware, sometimes simultaneously.
A cybercriminal gang have been arrested for spreading the Locky ransomware among hospitals... They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail...”
If this check failed, Locky would be served instead... Thus, we expect to see a different download location and likely a Locky payload.
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Ces pièces jointes pouvaient notamment être des archives zip ou 7zip contenant des scripts VBS ou Javascript à faire exécuter par ses victimes.
Ces pièces jointes pouvaient notamment être des archives zip ou 7zip contenant des scripts VBS ou Javascript... Ce dernier redirige la victime vers une URL d’un site légitime mais compromis.
It therefore distributed bugged Office documents via the DDE mechanism less than a month after the potential abuse of this feature became common knowledge.
Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process.
Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process.
HOOK INJECTION VIA SETWINDOWSHOOKEX... Malware can leverage hooking functionality to have their malicious DLL loaded upon an event getting triggered in a specific thread.
109 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
103 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware identified as a payload distributed through the Necurs spam botnet.
Referenced as an example ransomware family in a citation related to backup monitoring and ransomware risk; the content does not analyze Locky itself.
A ransomware family mentioned as one of the payloads delivered by Magnitude Exploit Kit.
Legacy ransomware family referenced only for historical comparison: a 2016 'Osiris' variant was based on Locky; the newly reported Osiris strain is stated to be unrelated.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.