EMZETT.
Login

Locky

In short: Locky is a ransomware that was spread massively by e-mail from 2016 and encrypted files.

In more detail: Locky came as an attachment in spam mails, usually a Word document with a macro or a script. After opening, it downloaded the actual malware and encrypted documents, images and databases. The files received the extension .locky.

In Depth

Technology

Locky used AES-128 for the files and RSA-2048 for the key. Without the attackers’ private key, decryption was practically impossible. It was distributed mainly through the Necurs botnet.

Ransom

Usually a few bitcoin (Bitcoin) were demanded, paid via a Tor page.

Protection

Disable macros in Office documents from unknown sources, treat attachments with suspicion, regular offline backups, keep systems up to date.

See also: Malware, GoldenEye, E-mail Attachments, Cryptojacking