Locky ransomware operates using the same delivery method for the downloader, with similar subject lines and attachments. Attackers also use the same botnets to deliver both Dridex and Locky ransomware, sometimes simultaneously.
Locky
Locky is a Windows ransomware family that emerged in 2016 and became one of the most prominent large-scale malspam-delivered crypto-extortion threats of its period.
Profile source: Mallory opens in a new tabLocky
Family profile
Locky is a Windows ransomware family that emerged in 2016 and became one of the most prominent large-scale malspam-delivered crypto-extortion threats of its period. It is closely associated with high-volume spam operations delivered through infrastructure such as the Necurs botnet and has been linked in multiple public reports to financially motivated activity clusters including TA505 and, more speculatively, Evil Corp. Locky was commonly distributed through phishing emails carrying malicious attachments such as macro-enabled Office documents, JavaScript downloaders in compressed archives, and other socially engineered file types. In some campaigns, Locky was delivered directly; in others it was fetched by intermediate downloaders such as QtLoader or by botnet-delivered loaders shared with Dridex operations.
Once executed, Locky encrypts victim files and presents ransom instructions, typically after contacting attacker infrastructure as part of its execution flow. Public reporting also documents anti-analysis and anti-debugging measures in some variants, as well as use of a domain generation algorithm for command-and-control resilience. Locky spawned multiple notable variants and closely related strains, including Zepto and Osiris, with Zepto widely assessed as an evolutionary extension of Locky sharing most of its code base and core encryption logic.
Locky campaigns relied heavily on social engineering themes such as invoices, receipts, order confirmations, and business documents, and were sent at very large scale across many sectors and geographies. The malware was observed affecting enterprises, public institutions, and healthcare organizations, including hospital-focused incidents. Locky also figured prominently in the broader evolution of cybercriminal operations that shifted from banking trojans toward ransomware monetization, and it remains a historically significant example of industrialized spam-driven ransomware distribution.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
Reported operators
Threat actors
5 named in public reportingLocky ransomware operates using the same delivery method for the downloader, with similar subject lines and attachments. Attackers also use the same botnets to deliver both Dridex and Locky ransomware, sometimes simultaneously.
A cybercriminal gang have been arrested for spreading the Locky ransomware among hospitals... They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail...”
If this check failed, Locky would be served instead... Thus, we expect to see a different download location and likely a Locky payload.
...as well as several ransomware strains including Locky, BitPaymer, Philadelphia, GlobeImposter, and Jaff on their targets' computers...
Exploited software
Vulnerabilities linked to Locky
3 CVEsMITRE ATT&CK
Locky in ATT&CK
28 distinct techniquesTechniques
28 techniquesReporting
Research mentioning Locky
Ransomware Group clop Hits: HONGHE-TECH.COM
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
Ransomware Group clop Hits: 9ALTITUDES.COM
Ransomware Group clop Hits: WATERLANDPE.COM
Ransomware Group clop Hits: NETPOWER.COM
Ransomware Group clop Hits: ALDOGROUP.COM (ALDOSHOES.COM)
Ransomware Group clop Hits: IRCO.COM
Ransomware Group clop Hits: LARGAN.COM.TW
Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs
SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.