the messages and the delivery suggest they were sent by threat actor TA505, known for sending large-scale Dridex, Locky, and GlobeImposter campaigns, among others, over the last four years.
Locky
Locky is a prominent Windows ransomware family that emerged in 2016 and became one of the defining large-scale extortion threats of that period.
Profile source: Mallory opens in a new tabLocky
Family profile
Locky is a prominent Windows ransomware family that emerged in 2016 and became one of the defining large-scale extortion threats of that period. It is closely associated with major malspam ecosystems and was widely distributed through high-volume email campaigns using invoice-themed or other business-themed lures, typically carrying macro-enabled Microsoft Office documents, compressed JavaScript attachments, or intermediary downloaders. Delivery activity has been linked to large spam botnet operations including Necurs, and multiple reports have associated Locky campaigns with threat actors such as TA505 and actors involved in major Dridex distribution activity. Locky was also observed being delivered through exploit-kit activity, including Magnitude EK, in addition to email-based distribution.
Once executed, Locky encrypts victim data on local, removable, and network-accessible drives and renames files using variant-specific extensions. Reported extensions across the family include .locky, .zepto, .odin, .thor, .aesir, .zzzzz, .lukitus, and .osiris, reflecting the family’s evolving campaigns and sub-variants. The malware then presents ransom instructions directing victims to attacker-controlled payment infrastructure, commonly via Tor-based services. Public reporting describes Locky as using strong hybrid cryptography, including RSA-2048 and AES-128, with key generation handled server-side, which historically made recovery without the attacker’s cooperation impractical.
Locky’s operators and distributors repeatedly adapted delivery and evasion techniques. Observed tradecraft included heavily obfuscated JavaScript, malformed MIME headers, misleading archive and file-extension tricks, junk files inside archives, and use of intermediate loaders such as RockLoader. Some variants and associated loaders incorporated anti-analysis and detection-evasion measures, including virtual-machine checks, code obfuscation, process staging, and UAC-bypass functionality in supporting components. Campaign reporting also noted overlap in infrastructure, botnets, and delivery methods with Dridex operations, and some sources attributed Locky-related activity to the same criminal ecosystem variously described as TA505 or Evil Corp, though such attribution is not uniformly resolved across all reporting.
Locky had significant real-world impact across sectors, including healthcare, education, and enterprise environments, and was notable for the scale of its spam distribution as well as its role in the commercialization of ransomware operations. Variants such as Diablo6, Lukitus, Zepto, Osiris, and others represent iterative development within the family rather than unrelated malware.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
Reported operators
Threat actors
2 named in public reportingLocky ransomware operates using the same delivery method for the downloader, with similar subject lines and attachments. Attackers also use the same botnets to deliver both Dridex and Locky ransomware, sometimes simultaneously.
Exploited software
Vulnerabilities linked to Locky
1 CVEsMITRE ATT&CK