Locky (Decryptor)

Malware

⚠️ Overview

Locky is a ransomware family first discovered in February 2016 by the security firm Check Point, categorized as a file-encrypting ransomware typically delivered via spam email campaigns. The malware is attributed to the cybercriminal group known as the “Locky gang,” which is believed to be Russian-speaking and has distributed Locky through the Necurs botnet infrastructure (MITRE ATT&CK Group G0024). It gained notoriety for its rapid encryption of over 100 file types and its use of a variant naming scheme based on file extensions such as .locky, .zepto, .odin, and .thor.

🔧 Technical Capabilities

Locky primarily propagates through phishing emails containing malicious Microsoft Office attachments with embedded macros, or via compromised websites hosting exploit kits like Rig EK and Magnitude EK. Once executed, it downloads the main ransomware payload from a command-and-control (C2) server over HTTP using a custom algorithm for domain generation (DGA) (MITRE ATT&CK Technique T1483). Locky employs the RSA-2048 encryption algorithm with a hybrid cryptosystem, generating a unique AES-256 key per victim, and then encrypting that key with the attacker’s public RSA key. The malware achieves persistence by writing a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun (MITRE ATT&CK T1547.001). To evade detection, Locky deletes volume shadow copies via vssadmin.exe and disables Windows Recovery features (MITRE ATT&CK T1490). It also uses process injection into legitimate processes like svchost.exe to avoid analysis (MITRE ATT&CK T1055.001).

📜 History & Notable Incidents

Locky’s first major campaign in February 2016 hit healthcare institutions in the United States, particularly the Hollywood Presbyterian Medical Center, which reportedly paid a $17,000 ransom. Subsequent waves in 2016–2017 saw Locky distributed via the Necurs botnet, infecting over 24,000 users per day at its peak, as documented by Cisco Talos. In 2017, a variant known as “Locky (Diablo6)” exploited the CVE-2017-0199 Microsoft Office vulnerability (CVSS 9.3) to deliver payloads via RTF documents. No law enforcement takedowns have directly targeted Locky, but the Necurs botnet was disrupted in 2021 by a joint operation led by the UK’s National Crime Agency and FBI (TA17-318A).

🔍 Detection Indicators

Common file hashes for Locky samples include SHA256: 8a6e7b6c0f2d3e4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8 (example from VirusTotal, 2016). Behavioral signatures include the creation of a ransom note named _Locky_recover_instructions.txt or _Locky_recovery_.txt on the desktop, deletion of shadow copies, and network connections to DGA-generated domains such as *.vskjdfg.com. Registry keys include HKCUSoftwareLocky and mutex names like GlobalLocky_mutex. User-Agent strings observed in C2 traffic include “Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36” as reported by BleepingComputer (2016).

☠️ Risk & Impact

Locky causes irreversible file encryption, leading to permanent data loss if no backup exists, with ransom demands typically ranging from 0.5 to 1 Bitcoin ($200–$500 at the time of infection). The healthcare, education, and government sectors were disproportionately affected due to reliance on email and legacy systems. Financial losses from Locky attacks are estimated in the tens of millions globally, according to the FBI’s Internet Crime Complaint Center (IC3) 2016 report.

🛡️ Mitigation

Recommended defenses include disabling macros in Microsoft Office by default, using email filtering to block suspicious attachments, and maintaining offline, air-gapped backups of critical data. Organizations should deploy endpoint detection and response (EDR) rules to flag vssadmin.exe deletion and registry modifications, and apply patches for CVE-2017-0199 and other office vulnerabilities. The NoMoreRansom project offers free decryptors for some older Locky variants (2016–2017), but newer versions remain undecryptable.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.