{"id":18343,"date":"2017-09-05T12:54:34","date_gmt":"2017-09-05T07:24:34","guid":{"rendered":"https:\/\/blog.resellerclub.com\/?p=18343"},"modified":"2026-05-21T10:47:07","modified_gmt":"2026-05-21T10:47:07","slug":"locky-ransomware-everything-you-need-to-know","status":"publish","type":"post","link":"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/","title":{"rendered":"Locky Ransomware: Everything You Need to Know"},"content":{"rendered":"<p><strong>What is Locky Ransomware?<\/strong><\/p>\n<p>After <a href=\"\/blog\/patching-windows-on-resellerclub-dedicated-servers-to-protect-against-the-wannacry-smb-attack\/\">WannaCry <\/a>and <a href=\"\/blog\/another-ransomware-attack-petya-makes-headlines\/\">Petya<\/a>, another ransomware seems to spreading like wildfire, taking a hold of computer systems all over the globe, this time it\u2019s being called Locky.<\/p>\n<p>The Computer Emergency and response team (CERT) under Government of India has raised an advisory on the spread of Locky Ransomware via spam emails.<\/p>\n<p>&nbsp;<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">CERT-In published Alert regarding the spam campaign spreading Locky ransomware <a href=\"https:\/\/t.co\/hzbuyDLjvB\">https:\/\/t.co\/hzbuyDLjvB<\/a><\/p>\n<p>\u2014 CERT-In (@IndianCERT) <a href=\"https:\/\/twitter.com\/IndianCERT\/status\/904210285832970244\">September 3, 2017<\/a><\/p><\/blockquote>\n<p>Quoted from <a href=\"http:\/\/www.cyberswachhtakendra.gov.in\/alerts\/locky_ransomware.html\">CERT-In <\/a><em>Locky is a ransomware that scramble the contents of a computer or server (associated network shares, both mapped and unmapped and removable media) and demands payment to unlock it &#8220;usually by anonymous decentralized virtual currency BITCOINS&#8221;.<\/em><\/p>\n<p>Locky is very similar to WannaCry in the way it caused massive uproar around the world.<\/p>\n<p>It came into picture in early 2016 and two days ago it was reported that a new wave of spam mails have started circulating again with common to spread variants of Locky ransomware, this time penetrating Indian systems as well. Latest reports indicate that over 23 million messages have been sent in this campaign.<\/p>\n<p>Locky Ransomware strikes your system when you least expect it. It locks your computer system and only unlocks it when a ransom demand is paid. Locky uses AES( Advanced Encryption Standard) algorithm to encrypt your system and this is only possible once you download the malicious attachment and Enable the Macros settings.<\/p>\n<p><strong>How does it propagate?<\/strong><\/p>\n<p>The primary mode of spreading of Locky is via spam emails. The email contains common subjects like \u2018documents\u2019, \u2018please print\u2019, \u2018photo\u2019, \u2018images\u2019, \u2018pictures\u2019 and \u2018scans\u2019 which may change depending on the target audience. Once you open this email, and click on the attachment variants of the ransomware automatically get downloaded to your computer.<\/p>\n<p>As soon as the variants are downloaded, your desktop background is changed with instructions to be followed and shows a \u2018.htm\u2019 file named &#8220;Lukitus[dot]htm&#8221;.<br \/>\nOnce the system is infected by Locky, all files are encrypted and string with random numbers with extension &#8221; [.]lukitus&#8221; or &#8220;[.]diablo6&#8221; is appended to the encrypted files. Lukitus is French for \u2018locking\u2019.<\/p>\n<p>The instructions contain installation of TOR browser (Onion Router Network) and visiting &#8220;.onion&#8221; sites. The users are then demanded to pay 0.5 Bitcoins to avail this decryption service that\u2019s equivalent to almost Rs. 1.5 lakh (INR).<\/p>\n<p>Furthermore, it has been reported that a spam campaign showing links to fake dropbox sites is being used to spread Locky variants. If the pages are viewed in Chrome or Firefox, they show a fake notification stating &#8220;you don&#8217;t have the HoeflerText font&#8221;. These fake notifications had an &#8220;update&#8221; button that returns a malicious JavaScript (.js) file. [1]\n<p>In a nutshell, what it does is this:<\/p>\n<ol>\n<li>You receive an email, with an attachment that when opened is a scrambled mess of words.<\/li>\n<li>At the top are the words, \u2018Enable Macros if the data encoding is incorrect.\u2019<\/li>\n<li>The moment you enable macros, instead of correcting the document, your system gets encrypted and Locky ransomware is activated and Windows ability to take live backup called Shadow copies is also compromised.<\/li>\n<li>Your wallpaper changes to \u2018How to decrypt\u2019 message displaying image.<\/li>\n<\/ol>\n<figure id=\"attachment_18345\" aria-describedby=\"caption-attachment-18345\" style=\"width: 625px\" class=\"wp-caption alignleft\"><a href=\"Locky \"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-18345 size-full\" src=\"\/blog\/wp-content\/uploads\/2017\/09\/locky.png\" width=\"625\" height=\"327\"><\/a><figcaption id=\"caption-attachment-18345\" class=\"wp-caption-text\">Locky Message<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><b>Recommendations against Locky:<\/b><\/p>\n<p>Here is a list of recommendations advised to the users to prevent Locky from compromising your computer.<\/p>\n<ul>\n<li>The foremost recommendation to users is to not to open any spam emails, or attachments as well as update anti-spam and block lists.<\/li>\n<li>Block malicious IP addresses.<\/li>\n<li>Do not download or open attachments which contains Zip files.<\/li>\n<li>Perform regular backup of your data, and store it on some other devices most preferably offline.<\/li>\n<li>Disable Macro in Microsoft Office applications \u2018Disable all macros with notification\u2019. Macros can run in Ms. Office applications only if the Macro settings are set to \u2018Enable all macros\u2019 or if the user manually enables it. This is done so because the email attachment comes in Macro Enabled form.<\/li>\n<li>Have an updated Antivirus installed on your personal as well as office systems.<\/li>\n<li>Don&#8217;t click on unnecessary popups while visiting websites which may contain Embedded JavaScript (.js) file which can download the ransomware.<\/li>\n<li>Don&#8217;t use administrative accounts for carrying out Business as Usual activities, which limits the rate of installation. Also disable remote Desktop Connections.<\/li>\n<li>Don&#8217;t visit malicious websites or blocked websites listed on the advisory at least.<\/li>\n<li>Update your operating systems, third party applications like browser, browser plugins and anti-virus software for latest security patches.<\/li>\n<\/ul>\n<p>Practice all the above recommended. In spite of this, if you suspect your computer system has been infected, contact your IT team and under no circumstances pay any ransom.<\/p>\n<p><strong>Reference:<\/strong><br \/>\n<a href=\"http:\/\/www.cyberswachhtakendra.gov.in\/alerts\/locky_ransomware.html\">http:\/\/www.cyberswachhtakendra.gov.in\/alerts\/locky_ransomware.html<\/a><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground:  !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 100% !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>What is Locky Ransomware? After WannaCry and Petya, another ransomware seems to spreading like wildfire, taking a hold of computer systems all over the globe, this time it\u2019s being called Locky. The Computer Emergency and response team (CERT) under Government of India has raised an advisory on the spread of Locky Ransomware via spam emails.<\/p>\n","protected":false},"author":75,"featured_media":18347,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[812,990,813,1533],"tags":[4705,1161,4697,4701,4417,176,960],"hashtags":[],"class_list":{"0":"post-18343","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-email","8":"category-news-en","9":"category-website-security-2","10":"category-tech","11":"tag-cert","12":"tag-cyber-attack","13":"tag-locky","14":"tag-macros","15":"tag-ransomware","16":"tag-virus","17":"tag-windows"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Locky Ransomware: Everything You Need to Know<\/title>\n<meta name=\"description\" content=\"Explore a complete guide to Locky ransomware, including infection methods, encrypted files, cyberattack risks, and effective ransomware protection tips.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Locky Ransomware: Everything You Need to Know\" \/>\n<meta property=\"og:description\" content=\"Explore a complete guide to Locky ransomware, including infection methods, encrypted files, cyberattack risks, and effective ransomware protection tips.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/\" \/>\n<meta property=\"og:site_name\" content=\"ResellerClub Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/profile.php?id=100005889763273\" \/>\n<meta property=\"article:published_time\" content=\"2017-09-05T07:24:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-21T10:47:07+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"H. Fatima\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/\",\"name\":\"ResellerClub Blog\",\"description\":\"Web Hosting &amp; Domains\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#webpage\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/\",\"name\":\"Locky Ransomware: Everything You Need to Know\",\"isPartOf\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#primaryimage\"},\"datePublished\":\"2017-09-05T07:24:34+00:00\",\"dateModified\":\"2026-05-21T10:47:07+00:00\",\"author\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/04f625d706ed889a739c8fdfe159375c\"},\"description\":\"Explore a complete guide to Locky ransomware, including infection methods, encrypted files, cyberattack risks, and effective ransomware protection tips.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.resellerclub.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Locky Ransomware: Everything You Need to Know\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/04f625d706ed889a739c8fdfe159375c\",\"name\":\"H. Fatima\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2020\/03\/IMG-20190220-WA0043-150x150.jpg\",\"contentUrl\":\"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2020\/03\/IMG-20190220-WA0043-150x150.jpg\",\"caption\":\"H. Fatima\"},\"description\":\"H. Fatima used to be an Engineer by profession and Writer by passion until she started pursuing full-time writing. She is presently a Content Marketeer at Newfold Digital (APAC). She mostly writes what she deeply perceives and analyses, it is her way of unwinding. Her interests include writing, reading (an avid reader), watching foreign-language movies and public speaking.\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/author\/h-fatima\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Locky Ransomware: Everything You Need to Know","description":"Explore a complete guide to Locky ransomware, including infection methods, encrypted files, cyberattack risks, and effective ransomware protection tips.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/","og_locale":"en_US","og_type":"article","og_title":"Locky Ransomware: Everything You Need to Know","og_description":"Explore a complete guide to Locky ransomware, including infection methods, encrypted files, cyberattack risks, and effective ransomware protection tips.","og_url":"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/","og_site_name":"ResellerClub Blog","article_publisher":"https:\/\/www.facebook.com\/profile.php?id=100005889763273","article_published_time":"2017-09-05T07:24:34+00:00","article_modified_time":"2026-05-21T10:47:07+00:00","twitter_card":"summary_large_image","twitter_misc":{"Written by":"H. Fatima","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.resellerclub.com\/blog\/#website","url":"https:\/\/www.resellerclub.com\/blog\/","name":"ResellerClub Blog","description":"Web Hosting &amp; Domains","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#primaryimage","inLanguage":"en-US","url":"","contentUrl":""},{"@type":"WebPage","@id":"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#webpage","url":"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/","name":"Locky Ransomware: Everything You Need to Know","isPartOf":{"@id":"https:\/\/www.resellerclub.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#primaryimage"},"datePublished":"2017-09-05T07:24:34+00:00","dateModified":"2026-05-21T10:47:07+00:00","author":{"@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/04f625d706ed889a739c8fdfe159375c"},"description":"Explore a complete guide to Locky ransomware, including infection methods, encrypted files, cyberattack risks, and effective ransomware protection tips.","breadcrumb":{"@id":"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.resellerclub.com\/blog\/locky-ransomware-everything-you-need-to-know\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.resellerclub.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Locky Ransomware: Everything You Need to Know"}]},{"@type":"Person","@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/04f625d706ed889a739c8fdfe159375c","name":"H. Fatima","image":{"@type":"ImageObject","@id":"https:\/\/www.resellerclub.com\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2020\/03\/IMG-20190220-WA0043-150x150.jpg","contentUrl":"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2020\/03\/IMG-20190220-WA0043-150x150.jpg","caption":"H. Fatima"},"description":"H. Fatima used to be an Engineer by profession and Writer by passion until she started pursuing full-time writing. She is presently a Content Marketeer at Newfold Digital (APAC). She mostly writes what she deeply perceives and analyses, it is her way of unwinding. Her interests include writing, reading (an avid reader), watching foreign-language movies and public speaking.","url":"https:\/\/www.resellerclub.com\/blog\/author\/h-fatima\/"}]}},"_links":{"self":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/18343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/users\/75"}],"replies":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/comments?post=18343"}],"version-history":[{"count":7,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/18343\/revisions"}],"predecessor-version":[{"id":41214,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/18343\/revisions\/41214"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/media?parent=18343"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/categories?post=18343"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/tags?post=18343"},{"taxonomy":"hashtags","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/hashtags?post=18343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}