{"id":1081,"date":"2016-11-11T16:21:59","date_gmt":"2016-11-11T16:21:59","guid":{"rendered":"https:\/\/myspybot.com\/?p=1081"},"modified":"2025-11-30T11:38:33","modified_gmt":"2025-11-30T11:38:33","slug":"locky-ransomware-evolution","status":"publish","type":"post","link":"https:\/\/myspybot.com\/locky-ransomware-evolution\/","title":{"rendered":"Locky ransomware evolution"},"content":{"rendered":"<p>There are ransomware samples out there whose devs cannot boast professional data encryption practices, which has allowed researchers to create workarounds for decrypting hostage files. Some examples include the Globe, DXXD, DMA Locker, and 7ev3n strains. On the other hand, there are ransom Trojans like Locky, which cripple victims\u2019 files beyond recovery. In that case, the only viable way to recover is to cough up a specific amount of cryptocurrency being extorted. Although this perpetrating program was discovered back in February 2016, it is still uncrackable nine months after.<\/p>\n<p>In order to be a moving target for security analysts, Locky is regularly updated. A total of five versions have been released up till now, each one featuring enhanced features to prevent reverse-engineering of the code and more robust crypto implementations. This article provides a comprehensive report on all variants of the Locky ransomware to date.<\/p>\n<h3>The newsmaking emergence<\/h3>\n<p>When <a href=\"https:\/\/myspybot.com\/decrypt-locky-files\/\" target=\"_blank\" rel=\"noopener\">the first edition of Locky<\/a> surfaced, security experts shortly found that its distribution relied on an ill-famed botnet called Necurs. Cybercriminals had leveraged this particular botnet earlier to spread Dridex, a Trojan that steals victims\u2019 e-banking credentials and other sensitive data. Furthermore, the operators of Locky even borrowed the same infection chain. The ransomware payload arrived with phishing emails pretending to be an invoice. The attached Microsoft Word document prompted the recipients to activate macros, which triggered the execution of the malicious routine on the computer.<\/p>\n<figure id=\"attachment_653\" aria-describedby=\"caption-attachment-653\" style=\"width: 620px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/07\/docm-file-security-warning.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/07\/docm-file-security-warning.png\" alt=\"Enabling macros leads to installation of Locky\" title=\"Enabling macros leads to installation of Locky\" width=\"620\" height=\"280\" class=\"size-full wp-image-653\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/07\/docm-file-security-warning.png 620w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/07\/docm-file-security-warning-300x135.png 300w\" sizes=\"(max-width: 620px) 100vw, 620px\" \/><\/a><figcaption id=\"caption-attachment-653\" class=\"wp-caption-text\">Enabling macros leads to installation of Locky<\/figcaption><\/figure>\n<p>Upon intrusion, Locky version 1 would scan the hard disk, removable drives and mapped network shares for the user\u2019s personal files. Everything detected in the course of this data scouring was subject to strong encryption. The ransomware used two different cryptosystems to deny the availability of files, namely <a href=\"https:\/\/myspybot.com\/remove-rsa-2048-aes-128-virus\/\" target=\"_blank\" rel=\"noopener\">RSA-2048 and AES-128<\/a>. Filenames would change as well, morphing into unrecognizable entities similar to <strong>7185F1FG7823F1F53N94DBB58671A345.locky<\/strong>. These were strings consisting of 32 hexadecimal chars followed by the .locky extension.<\/p>\n<figure id=\"attachment_630\" aria-describedby=\"caption-attachment-630\" style=\"width: 800px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/help_instructions-bmp.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/help_instructions-bmp.png\" alt=\"Modified desktop wallpaper\" title=\"Modified desktop wallpaper\" width=\"800\" height=\"417\" class=\"size-full wp-image-630\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/help_instructions-bmp.png 800w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/help_instructions-bmp-300x156.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/help_instructions-bmp-768x400.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/help_instructions-bmp-620x323.png 620w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/a><figcaption id=\"caption-attachment-630\" class=\"wp-caption-text\">Modified desktop wallpaper<\/figcaption><\/figure>\n<p>The ransomware also added ransom notes called \u201c<strong>_Locky_recover_instructions.txt<\/strong>\u201d to encoded folders and the machine\u2019s desktop. It also changed the desktop background to a pre-designed image holding the same recovery instructions, including the user\u2019s personal ID. According to these, the victim had to visit a site called the Locky Decryptor Page and use further details on it to submit 0.5 Bitcoins to the criminals. At that point, this sample stood out from the crowd because its code had no apparent flaws and the cryptographic facet was immaculate.<\/p>\n<h3>Offline encryption experiments of the Zepto variant<\/h3>\n<p>Locky version 2 went live at the beginning of August 2016. It combined deep-level tweaks with external adjustments made to the original infection. This edition concatenated the <a href=\"https:\/\/myspybot.com\/zepto-file-virus\/\" target=\"_blank\" rel=\"noopener\">.zepto extension<\/a> to one\u2019s encrypted files, which is why the security community called it this way. As opposed to its precursor, the updated ransomware modified filenames according to a new pattern. Specifically, it replaced them with the same number of characters (32) but broke the strings down into five parts with hyphens linking them. For instance, a random affected file assumed a form like this: <strong>015DBF10-32D2-FNI4-F058-F286E992B714.zepto<\/strong>.<\/p>\n<figure id=\"attachment_632\" aria-describedby=\"caption-attachment-632\" style=\"width: 780px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/zepto-files.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/zepto-files.png\" alt=\"Files encoded by the Zepto edition of Locky\" title=\"Files encoded by the Zepto edition of Locky\" width=\"780\" height=\"500\" class=\"size-full wp-image-632\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/zepto-files.png 780w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/zepto-files-300x192.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/zepto-files-768x492.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/06\/zepto-files-620x397.png 620w\" sizes=\"(max-width: 780px) 100vw, 780px\" \/><\/a><figcaption id=\"caption-attachment-632\" class=\"wp-caption-text\">Files encoded by the Zepto edition of Locky<\/figcaption><\/figure>\n<p>A new set of ransom manuals is another change included in the Zepto release. A combo of files called \u201c<strong>_HELP_instructions.html<\/strong>\u201d and \u201c<strong>_HELP_instructions.bmp<\/strong>\u201d took over the previous \u201c<strong>_Locky_recover_instructions.txt<\/strong>\u201d note. The structure of these help documents remained the same. Another invariable thing was the desktop background, which reflected the preliminary recovery steps just like before.<\/p>\n<figure id=\"attachment_1090\" aria-describedby=\"caption-attachment-1090\" style=\"width: 700px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/help_instructions-html.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/help_instructions-html.png\" alt=\"_HELP_instructions.html ransom note\" title=\"_HELP_instructions.html ransom note\" width=\"700\" height=\"580\" class=\"size-full wp-image-1090\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/help_instructions-html.png 700w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/help_instructions-html-300x249.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/help_instructions-html-620x514.png 620w\" sizes=\"(max-width: 700px) 100vw, 700px\" \/><\/a><figcaption id=\"caption-attachment-1090\" class=\"wp-caption-text\">_HELP_instructions.html ransom note<\/figcaption><\/figure>\n<p>What did undergo an alteration, though, was the encryption method leveraged by some affiliates of the Locky hoax. The bad guys tried their hand at applying a cipher without requesting a public crypto key from a Command and Control server. When in this mode dubbed \u201cautopilot\u201d, the infection could do its filthy data scrambling job without being detected by firewalls and antimalware suites, which may identify suspicious traffic between an offending program and its C2 page. However, this technique had some shortcomings for the attackers. The main one is that it became impossible to track the number of ransomware installations, so the statistics weren\u2019t as informative.<\/p>\n<p>The proliferation method used to infect computers with Zepto was no longer backed by macros exploitation. Instead, the extortionists leveraged spam emails with ZIP archives that contained JS or WSF files. These malicious entities would be masqueraded as invoices, receipts, CVs or cancellation requests. Once a user clicked on them, the bad scripts would stealthily install the ransomware onto the system.<\/p>\n<h3>Locky version 3: a step back cryptography-wise<\/h3>\n<p>When it seemed that Locky operators were up to switching to offline encryption irrevocably, the third <a href=\"https:\/\/myspybot.com\/odin-virus\/\" target=\"_blank\" rel=\"noopener\">\u201cOdin\u201d variant<\/a> proved the opposite. The criminals in charge reversed to the use of Command and Control servers for secret keys. It\u2019s hard to say for sure why this move backward happened. Some researchers speculate that the black hats couldn\u2019t tolerate the fact that the distribution statistics were incomplete. This edition appeared in late September, about two months after its forerunner Zepto emerged.<\/p>\n<figure id=\"attachment_897\" aria-describedby=\"caption-attachment-897\" style=\"width: 820px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/09\/odin-ransomware.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/09\/odin-ransomware.png\" alt=\"The Odin variant of Locky\" title=\"The Odin variant of Locky\" width=\"820\" height=\"460\" class=\"size-full wp-image-897\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/09\/odin-ransomware.png 820w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/09\/odin-ransomware-300x168.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/09\/odin-ransomware-768x431.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/09\/odin-ransomware-620x348.png 620w\" sizes=\"(max-width: 820px) 100vw, 820px\" \/><\/a><figcaption id=\"caption-attachment-897\" class=\"wp-caption-text\">The Odin variant of Locky<\/figcaption><\/figure>\n<p>Along with downgrading the file encoding principle, Locky developers made a few more changes to their program. It appended the .odin tail to every skewed file. Filenames got renamed according to the same pattern that the Odin spinoff used. Victims learned the recovery steps from ransom manuals now named \u201c<strong>_HOWDO_text.html<\/strong>\u201d and \u201c<strong>_HOWDO_text.bmp<\/strong>\u201d. The ransom was still payable in Bitcoins and amounted to 0.5 BTC. To submit it, the infected users had to visit the already familiar Locky Decryptor page.<\/p>\n<h3>The short-lived \u201cShit\u201d version<\/h3>\n<p>Looking back at the fourth edition of Locky, it\u2019s not clear whether it was a joke or a failed spinoff. This one was <a href=\"https:\/\/myspybot.com\/shit-files-virus\/\" target=\"_blank\" rel=\"noopener\">discovered<\/a> in late October. Its main distinguishing property was the .shit extension being added to the names of encrypted files. The ransom instructions were provided through documents called \u201c<strong>_WHAT_is.html<\/strong>\u201d and \u201c<strong>_WHAT_is.bmp<\/strong>\u201d. So much for the external modifications.<\/p>\n<figure id=\"attachment_949\" aria-describedby=\"caption-attachment-949\" style=\"width: 860px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/demands-of-the-shit-ransomware.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/demands-of-the-shit-ransomware.png\" alt=\"Adverse effects of the .shit file ransomware attack\" title=\"Adverse effects of the .shit file ransomware attack\" width=\"860\" height=\"510\" class=\"size-full wp-image-949\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/demands-of-the-shit-ransomware.png 860w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/demands-of-the-shit-ransomware-300x178.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/demands-of-the-shit-ransomware-768x455.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/demands-of-the-shit-ransomware-620x368.png 620w\" sizes=\"(max-width: 860px) 100vw, 860px\" \/><\/a><figcaption id=\"caption-attachment-949\" class=\"wp-caption-text\">Adverse effects of the .shit file ransomware attack<\/figcaption><\/figure>\n<p>The propagation methodology exhibited a clear-cut focus on the spam vector. By leveraging a large botnet, the perpetrators launched a massive spam campaign that generated thousands of rogue emails on a daily basis. These emails were intended to dupe people into opening a malicious attachment that came in the form of a JS, WSF or HTA file enclosed within a ZIP archive. A significant change regarding the data encoding part of the modus operandi was that this variant switched back to the \u201cautopilot\u201d mode. The malefactors have been, obviously, trying to strike a golden mean between code obfuscation and stats tracking, so they keep experimenting with offline crypto.<\/p>\n<h3>Thor, another evil character in the Locky saga<\/h3>\n<p>It took Locky devs a record-breaking time span of under 24 hours to switch from the .shit extension variant to a new edition. The successor uses the <a href=\"https:\/\/myspybot.com\/thor-virus-files\/\" target=\"_blank\" rel=\"noopener\">.thor string<\/a> to label one\u2019s affected files. The crooks leverage an encrypted DLL installer to execute the ransomware on computers. The configuration file contains a number of interesting hard-coded parameters. One of them instructs the infection to cease an attack if it discovers that the target system uses Russian as the default interface language. Furthermore, almost half of the Command and Control servers are located in Russia. These may be indicators of the criminals\u2019 origin.<\/p>\n<figure id=\"attachment_960\" aria-describedby=\"caption-attachment-960\" style=\"width: 860px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/thor-ransomware-effects.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/thor-ransomware-effects.png\" alt=\"The Thor ransomware assault aftermath\" title=\"The Thor ransomware assault aftermath\" width=\"860\" height=\"460\" class=\"size-full wp-image-960\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/thor-ransomware-effects.png 860w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/thor-ransomware-effects-300x160.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/thor-ransomware-effects-768x411.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/thor-ransomware-effects-620x332.png 620w\" sizes=\"(max-width: 860px) 100vw, 860px\" \/><\/a><figcaption id=\"caption-attachment-960\" class=\"wp-caption-text\">The Thor ransomware assault aftermath<\/figcaption><\/figure>\n<p>The Thor iteration transforms one\u2019s documents, images, databases, videos and other personal files into entries like <strong>ST8DRHBA-FG1M-XG4S-00F9-0B9157A80190.thor<\/strong>. Consequently, not only is it impossible to open them due to cryptographic changes, but it\u2019s also unfeasible to work out what specific objects have been encoded. The ransomware drops decryption help files called \u201c<strong>_WHAT_is.html\/.bmp<\/strong>\u201d. As before, these manuals, along with a warning wallpaper on the desktop, tell the victim to follow one of several available Tor links and thus visit the Locky Decryptor page.<\/p>\n<figure id=\"attachment_953\" aria-describedby=\"caption-attachment-953\" style=\"width: 860px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/locky-decryptor.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/locky-decryptor.png\" alt=\"Locky Decryptor page\" title=\"Locky Decryptor page\" width=\"860\" height=\"780\" class=\"size-full wp-image-953\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/locky-decryptor.png 860w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/locky-decryptor-300x272.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/locky-decryptor-768x697.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/10\/locky-decryptor-620x562.png 620w\" sizes=\"(max-width: 860px) 100vw, 860px\" \/><\/a><figcaption id=\"caption-attachment-953\" class=\"wp-caption-text\">Locky Decryptor page<\/figcaption><\/figure>\n<p>The size of the ransom is still 0.5 Bitcoins, or about 350 USD. Overall, the use of digital cash is an immutable trend with online extortionists, because it helps them stay on the loose due to its inherent anonymity attributes. If the rest of the attack technicalities, including the data encryption process, are implemented immaculately, a ransomware sample is double trouble. Unfortunately, all of Locky\u2019s spinoffs are like that.<\/p>\n<h3>The Aesir descendant of Locky<\/h3>\n<p>The next interjacent strain of the Locky epidemic continues the Norse mythology theme, where <a href=\"https:\/\/myspybot.com\/aesir-decryptor\/\" target=\"_blank\" rel=\"noopener\">Aesir<\/a> denotes a pantheon of warrior gods. In ransomware terms, this word serves as the new extension being subjoined to one\u2019s encrypted files. This variant replaces the name of a random scrambled entry with hexadecimal characters according to the following pattern: <strong>[8_chars]-[4_chars]-[4_chars]-[4_chars]-[12_chars].aesir<\/strong>. Compared to the previous Locky spinoff, the renaming template is identical except for the extension.<\/p>\n<figure id=\"attachment_1113\" aria-describedby=\"caption-attachment-1113\" style=\"width: 860px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/aesir-variant.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/aesir-variant.png\" alt=\"Locky\u2019s Aesir variant\" title=\"Locky\u2019s Aesir variant\" width=\"860\" height=\"440\" class=\"size-full wp-image-1113\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/aesir-variant.png 860w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/aesir-variant-300x153.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/aesir-variant-768x393.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/aesir-variant-620x317.png 620w\" sizes=\"(max-width: 860px) 100vw, 860px\" \/><\/a><figcaption id=\"caption-attachment-1113\" class=\"wp-caption-text\">Locky\u2019s Aesir variant<\/figcaption><\/figure>\n<p>The Aesir edition proliferates over email spam and a fairly uncommon Facebook phishing trick. The former method mainly relies on phony messages with the subject \u201cSpam mailout\u201d that misinform a victim of suspicious activity allegedly emanating from their address. The attachment, which is claimed to be the contents and logging of these purported spam messages, will execute the ransomware as soon as the unsuspecting recipient opens it. The distribution campaign on Facebook revolves around a malicious .svg image file that\u2019s sent to users over Facebook\u2019s Instant Messaging system.<\/p>\n<figure id=\"attachment_1112\" aria-describedby=\"caption-attachment-1112\" style=\"width: 860px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/spam-email-distributing-aesir-virus.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/spam-email-distributing-aesir-virus.png\" alt=\"Rogue spam mailout email distributing the Aesir virus\" title=\"Rogue spam mailout email distributing the Aesir virus\" width=\"860\" height=\"591\" class=\"size-full wp-image-1112\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/spam-email-distributing-aesir-virus.png 860w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/spam-email-distributing-aesir-virus-300x206.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/spam-email-distributing-aesir-virus-768x528.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/spam-email-distributing-aesir-virus-620x426.png 620w\" sizes=\"(max-width: 860px) 100vw, 860px\" \/><\/a><figcaption id=\"caption-attachment-1112\" class=\"wp-caption-text\">Rogue spam mailout email distributing the Aesir virus<\/figcaption><\/figure>\n<p>The ransom notes created by the Aesir variant convey the same instructions as before. Their names, however, have been changed to <strong>-INSTRUCTION.html<\/strong>, <strong>_[random_number]-INSTRUCTION.html<\/strong>, and <strong>-INSTRUCTION.bmp<\/strong>. The desktop background with a warning message didn\u2019t undergo any tweaks. Unfortunately, one more thing that the .aesir file ransomware edition has inherited from its forerunners is professional crypto. It is therefore still uncrackable, so users should be on the lookout for spam received over email or via social networking sites.<\/p>\n<h3>New derivative using the .zzzzz extension<\/h3>\n<p>The first spam wave disseminating the <a href=\"https:\/\/myspybot.com\/zzzzz-file\/\" target=\"_blank\" rel=\"noopener\">.zzzzz file variant<\/a> of Locky was spotted on November 24, 2016. Most of these rogue emails were camouflaged as order receipts and ISP complaints. The social engineering component of the latter theme was based on purported violations of an Internet Service Provider\u2019s terms of service through spam traffic allegedly emanating from the recipient\u2019s computer. This is irony of a sort \u2013 actual spam emails accusing users of sending spam. Strangely enough, it works.<\/p>\n<figure id=\"attachment_1123\" aria-describedby=\"caption-attachment-1123\" style=\"width: 860px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/zzzzz-ransomware.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/zzzzz-ransomware.png\" alt=\"Locky crippling files with the .zzzzz extension\" title=\"Locky crippling files with the .zzzzz extension\" width=\"860\" height=\"430\" class=\"size-full wp-image-1123\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/zzzzz-ransomware.png 860w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/zzzzz-ransomware-300x150.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/zzzzz-ransomware-768x384.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/zzzzz-ransomware-620x310.png 620w\" sizes=\"(max-width: 860px) 100vw, 860px\" \/><\/a><figcaption id=\"caption-attachment-1123\" class=\"wp-caption-text\">Locky crippling files with the .zzzzz extension<\/figcaption><\/figure>\n<p>The phish would engage ZIP attachments with JavaScript objects inside. When opened, the JS file downloads a malicious DLL and configures the host system to execute it with a Windows host process called Rundll32. This knotty workflow is implemented for a reason: it contributes to the AV evasion part of the ransomware compromise.<\/p>\n<p>Just like the previous version, the Zzzzz alias of Locky scrambles filenames using randomly generated hexadecimal characters. Furthermore, it sticks with the same ransom note names, which are <strong>-INSTRUCTION.html<\/strong>, <strong>_[random_number]-INSTRUCTION.html<\/strong>, and <strong>-INSTRUCTION.bmp<\/strong>. On the outside, the only conspicuous change is the .zzzzz file extension. Another cross-version common denominator is that the InfoSec community is still helpless when it comes to decrypting Locky-mutilated data.<\/p>\n<h3>Mythology theme revived in the Osiris variant<\/h3>\n<p>Having stepped away from the mythological version-naming paradigm for a while, Locky devs opted back in. The <a href=\"https:\/\/myspybot.com\/osiris-files-virus\/\" target=\"_blank\" rel=\"noopener\">.osiris file edition<\/a> of the ransomware was out on December 5, 2016. It brought about several novel things as compared to the Zzzzz predecessor. First of all, the .osiris extension makes a whole lot more sense in the overall Locky family context. Secondly, the new iteration leaves a different set of ransom manuals, namely <strong>OSIRIS-[4_chars].htm<\/strong> and <strong>OSIRIS.bmp<\/strong>. The BMP file replaces the victim\u2019s original desktop wallpaper.<\/p>\n<figure id=\"attachment_1191\" aria-describedby=\"caption-attachment-1191\" style=\"width: 860px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/12\/encrypted-osiris-files.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/12\/encrypted-osiris-files.png\" alt=\"Ransom note and encrypted .osiris files in a folder\" title=\"Ransom note and encrypted .osiris files in a folder\" width=\"860\" height=\"430\" class=\"size-full wp-image-1191\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/12\/encrypted-osiris-files.png 860w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/12\/encrypted-osiris-files-300x150.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/12\/encrypted-osiris-files-768x384.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/12\/encrypted-osiris-files-620x310.png 620w\" sizes=\"(max-width: 860px) 100vw, 860px\" \/><\/a><figcaption id=\"caption-attachment-1191\" class=\"wp-caption-text\">Ransom note and encrypted .osiris files in a folder<\/figcaption><\/figure>\n<p>The filename tweaking principle underwent a noticeable modification, too. The ransomware substitutes the initial filenames with 36 hexadecimal characters, whereas the precursors would use 32. Moreover, the five groups of these characters are now separated by double dashes rather than single ones. It\u2019s hard to say why this particular change took place, but it\u2019s certainly a distinguishing feature of the Osiris spinoff.<\/p>\n<figure id=\"attachment_1215\" aria-describedby=\"caption-attachment-1215\" style=\"width: 799px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/osiris-excel-macros.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/osiris-excel-macros.png\" alt=\"Excel macros are used to execute the Osiris variant of Locky\" title=\"Excel macros are used to execute the Osiris variant of Locky\" width=\"799\" height=\"514\" class=\"size-full wp-image-1215\" srcset=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/osiris-excel-macros.png 799w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/osiris-excel-macros-300x193.png 300w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/osiris-excel-macros-768x494.png 768w, https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/osiris-excel-macros-620x399.png 620w\" sizes=\"(max-width: 799px) 100vw, 799px\" \/><\/a><figcaption id=\"caption-attachment-1215\" class=\"wp-caption-text\">Excel macros are used to execute the Osiris variant of Locky<\/figcaption><\/figure>\n<p>One more thing that makes this edition stand out from the crowd is the unusual spam campaign distributing it. The outlaws in charge are dispersing emails with tricky Microsoft Excel documents on board. These are wrongfully claimed to be invoices, so the targeted people may get curious to see what\u2019s inside. The spreadsheet turns out to be blank, with a security warning at the top recommending the user to enable Excel macros. By clicking the \u201cEnable Content\u201d button on the alert, the unsuspecting recipient triggers a macro that downloads the Osiris payload and runs it on the computer.<\/p>\n<p>Unfortunately, the threat actors are tech-savvy enough to deploy the cryptographic part of their attacks immaculately, so researchers are yet to create a free decryptor. If there are no file backups available, those who fall victim to the Osiris ransomware may have to pay 0.5 Bitcoins to the malefactors.<\/p>\n<h3>Bottom Line<\/h3>\n<p>When it comes to the Locky ransomware campaign, the security community is confronted with a skilled and very tech-savvy adversary. There are no weak links in the way this infection encodes data. To top it off, it erases Shadow Volume Copies of files in order to counter one of the most viable workarounds for data recovery. As the malady evolves, it gets better at evading AVs and assumes improved characteristics to keep IT experts from analyzing it in a virtual machine environment.<\/p>\n<p>Ultimately, everyone is much better off focusing on ransomware prevention. The easiest and most worthwhile tips to protect yourself against this epidemic are as follows: don\u2019t click on spam attachments, keep your firewall enabled at all times, apply software patches and antimalware updates once they are available, and of course back up the most valuable files.<\/p>\n<div class=\"bdaia-separator se-dotted\" style=\"margin-top:15px !important;margin-bottom:80px !important;\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>There are ransomware samples out there whose devs cannot boast professional data encryption practices, which has allowed researchers to create workarounds for decrypting hostage files. Some examples include the Globe, DXXD, DMA Locker, and 7ev3n strains. On the other hand, there are ransom Trojans like Locky, which cripple victims\u2019 files beyond recovery. In that case, \u2026<\/p>\n","protected":false},"author":1,"featured_media":5513,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_stopmodifiedupdate":false,"_modified_date":"","rating_form_position":"","rating_results_position":"","mr_structured_data_type":"","footnotes":""},"categories":[21],"tags":[22],"acf":{"campaignid":"no","virusname":"","virusname0":"","virusname1":"","virusname2":"","virusname3":"","virusname4":"","virusname5":"","virustype":"","virustype0":"","virustype1":"","virustype2":"","virustype3":"","virustype4":"","virustype5":"","device":"","softtype":"","methods-to-restore-title":"","manual-removal-title":"","resetting-browsers-title":"","automatic-removal-title":"","faq":"","evolution":"","final-check-title":"","remove-from-chrome-title":"","remove-from-firefox-title":"","remove-from-explorer-title":"","remove-from-android-title":"","remove-using-cmd-title":"","remove-using-controlpanel-title":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Locky ransomware evolution - MySpyBot<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/myspybot.com\/locky-ransomware-evolution\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Locky ransomware evolution - MySpyBot\" \/>\n<meta property=\"og:description\" content=\"There are ransomware samples out there whose devs cannot boast professional data encryption practices, which has allowed researchers to create workarounds for decrypting hostage files. Some examples include the Globe, DXXD, DMA Locker, and 7ev3n strains. On the other hand, there are ransom Trojans like Locky, which cripple victims\u2019 files beyond recovery. In that case, \u2026\" \/>\n<meta property=\"og:url\" content=\"https:\/\/myspybot.com\/locky-ransomware-evolution\/\" \/>\n<meta property=\"og:site_name\" content=\"MySpyBot\" \/>\n<meta property=\"article:published_time\" content=\"2016-11-11T16:21:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-30T11:38:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/locky-evolution.png\" \/>\n\t<meta property=\"og:image:width\" content=\"850\" \/>\n\t<meta property=\"og:image:height\" content=\"491\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Will Wisser\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Will Wisser\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Locky ransomware evolution - MySpyBot","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/myspybot.com\/locky-ransomware-evolution\/","og_locale":"en_US","og_type":"article","og_title":"Locky ransomware evolution - MySpyBot","og_description":"There are ransomware samples out there whose devs cannot boast professional data encryption practices, which has allowed researchers to create workarounds for decrypting hostage files. Some examples include the Globe, DXXD, DMA Locker, and 7ev3n strains. On the other hand, there are ransom Trojans like Locky, which cripple victims\u2019 files beyond recovery. In that case, \u2026","og_url":"https:\/\/myspybot.com\/locky-ransomware-evolution\/","og_site_name":"MySpyBot","article_published_time":"2016-11-11T16:21:59+00:00","article_modified_time":"2025-11-30T11:38:33+00:00","og_image":[{"width":850,"height":491,"url":"https:\/\/myspybot.com\/wp-content\/uploads\/2016\/11\/locky-evolution.png","type":"image\/png"}],"author":"Will Wisser","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Will Wisser","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/myspybot.com\/locky-ransomware-evolution\/","url":"https:\/\/myspybot.com\/locky-ransomware-evolution\/","name":"Locky ransomware evolution - MySpyBot","isPartOf":{"@id":"https:\/\/myspybot.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/myspybot.com\/locky-ransomware-evolution\/#primaryimage"},"image":{"@id":"https:\/\/myspybot.com\/locky-ransomware-evolution\/#primaryimage"},"thumbnailUrl":"https:\/\/myspybot.com\/wp-content\/uploads\/2025\/11\/locky-ransomware-evolution-locky-ransomware-evolution-featured.png","datePublished":"2016-11-11T16:21:59+00:00","dateModified":"2025-11-30T11:38:33+00:00","author":{"@id":"https:\/\/myspybot.com\/#\/schema\/person\/f9391b7edcfb6793e7f51d87eeac082b"},"breadcrumb":{"@id":"https:\/\/myspybot.com\/locky-ransomware-evolution\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/myspybot.com\/locky-ransomware-evolution\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/myspybot.com\/locky-ransomware-evolution\/#primaryimage","url":"https:\/\/myspybot.com\/wp-content\/uploads\/2025\/11\/locky-ransomware-evolution-locky-ransomware-evolution-featured.png","contentUrl":"https:\/\/myspybot.com\/wp-content\/uploads\/2025\/11\/locky-ransomware-evolution-locky-ransomware-evolution-featured.png","width":850,"height":491,"caption":"Locky ransomware evolution"},{"@type":"BreadcrumbList","@id":"https:\/\/myspybot.com\/locky-ransomware-evolution\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/myspybot.com\/"},{"@type":"ListItem","position":2,"name":"Locky ransomware evolution"}]},{"@type":"WebSite","@id":"https:\/\/myspybot.com\/#website","url":"https:\/\/myspybot.com\/","name":"MySpyBot","description":"Keep an eye on the important computer security stuff","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/myspybot.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/myspybot.com\/#\/schema\/person\/f9391b7edcfb6793e7f51d87eeac082b","name":"Will Wisser","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/myspybot.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6247ff0634fa21676b3387d535d23eb4?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6247ff0634fa21676b3387d535d23eb4?s=96&d=mm&r=g","caption":"Will Wisser"}}]}},"multi-rating":{"mr_rating_results":[]},"_links":{"self":[{"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/posts\/1081"}],"collection":[{"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/comments?post=1081"}],"version-history":[{"count":0,"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/posts\/1081\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/media\/5513"}],"wp:attachment":[{"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/media?parent=1081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/categories?post=1081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/myspybot.com\/wp-json\/wp\/v2\/tags?post=1081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}