
August saw a new wave of spam emails being circulated with variants of the Locky ransomware. Reportedly, over 23 million emails of this nature have been sent under common subject lines such as “Please print”, “Documents”, “Scans”, “Photos”, “Pictures” and “Images” in just 24 hours. The perpetrators of this menace have been demanding a ransom of half a bitcoin, which is presently equivalent to $2,150, to install a special software which is supposed to be the “Locky decryptor”.
What is Locky?
First released in 2016, Locky is an email-based ransomware malware which is delivered through email attachments in the form of a .zip file, fake links to Dropbox locations and even fake voice mail messages. These files contain malicious ‘macros’ – a virus that is written in a programming language which is embedded inside a software application. What basically happens is that the user opens this attachment and finds a block of meaningless text. This text consists of a sentence that says – “Enable macro if data encoding is incorrect,” a social engineering technique. If the user opens these attachments, his/her machine becomes fully encrypted, leaving all information completely inaccessible.
Preventive Measures
Followed by WannaCry and Petya, Locky is touted to be one of the largest malware attacks in the second half of 2017. The threat of this malware seeping into the corporate networks is still looming over our heads and here’s what we can do to prevent it from crippling us: