Locky is a Windows ransomware family that rose to prominence in 2016 through very large malspam operations and remained widely detected for years afterward. It is closely associated with high-volume email-driven delivery ecosystems and has been linked in public reporting to operators and affiliates connected with TA505, Evil Corp, and the Necurs botnet, although attribution varies by campaign. Locky has also been discussed in relation to Dridex distribution infrastructure, with overlapping lures, attachments, and botnet delivery observed in some operations.
Locky is primarily delivered through phishing and spam campaigns using malicious attachments such as macro-enabled Office documents, JavaScript downloaders inside archives, executable payloads, and other socially engineered files. In some campaigns, first-stage downloaders or loaders such as QtLoader were used before Locky was retrieved as a later-stage payload. Campaigns commonly used invoice, receipt, order, and business-document themes to induce execution.
Once executed, Locky encrypts victim files and presents ransom instructions. Public reporting describes multiple Locky variants and related extensions, including Zepto and Osiris as Locky variants, and notes that Zepto shares extensive code and behavioral overlap with Locky. Locky operators also used domain generation algorithm infrastructure in some versions to support command-and-control resilience. Anti-analysis and anti-debugging measures have been observed in certain Locky campaigns and closely related variants.
Locky has been used against a broad range of victims globally, including enterprises, financial-sector targets, hospitals, and other public-sector organizations. It was one of the most prominent ransomware families of the mid-2010s and has been referenced in ransomware-as-a-service discussions, though the exact operational model varied across reporting. Some campaigns also leveraged a Windows local privilege escalation exploit, CVE-2015-1701. Later reporting noted a flawed revival campaign that mainly affected older Windows versions because the unpacking routine failed on newer systems with modern protections enabled.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Similar to techniques utilized by Dridex and Locky in mid-2017, the PDF contained an embedded RTF file which contains an embedded remote object that attacks CVE-2017-8579.
CVE-2015-1701 Classification: 1-Day Basic Description: CreateWindow callback validation error Used by the following malware families: Locky | CVE-2015-1701 ... Used by the following malware families: Locky.
CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Locky ransomware operates using the same delivery method for the downloader, with similar subject lines and attachments. Attackers also use the same botnets to deliver both Dridex and Locky ransomware, sometimes simultaneously.
Locky ransomware operates using the same delivery method for the downloader, with similar subject lines and attachments. Attackers also use the same botnets to deliver both Dridex and Locky ransomware, sometimes simultaneously.
A cybercriminal gang have been arrested for spreading the Locky ransomware among hospitals... They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail...”
If this check failed, Locky would be served instead... Thus, we expect to see a different download location and likely a Locky payload.
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Ces pièces jointes pouvaient notamment être des archives zip ou 7zip contenant des scripts VBS ou Javascript à faire exécuter par ses victimes.
Ces pièces jointes pouvaient notamment être des archives zip ou 7zip contenant des scripts VBS ou Javascript... Ce dernier redirige la victime vers une URL d’un site légitime mais compromis.
It therefore distributed bugged Office documents via the DDE mechanism less than a month after the potential abuse of this feature became common knowledge.
Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process.
Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process.
HOOK INJECTION VIA SETWINDOWSHOOKEX... Malware can leverage hooking functionality to have their malicious DLL loaded upon an event getting triggered in a specific thread.
108 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
93 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example ransomware family in a citation related to backup monitoring and ransomware risk; the content does not analyze Locky itself.
A ransomware family mentioned as one of the payloads delivered by Magnitude Exploit Kit.
Legacy ransomware family referenced only for historical comparison: a 2016 'Osiris' variant was based on Locky; the newly reported Osiris strain is stated to be unrelated.
Legacy ransomware family referenced only to clarify that the newly reported Osiris is not related to the 2016 Osiris/Locky iteration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.