Throughout the year, Forcepoint’s researchers been monitoring key milestones in Locky’s evolution; from its birth in February and the addition of virtual machine (VM) and analysis tool countermeasures in June, to its use of off line encryption in July and an intermediate downloader in September.
Locky is distributed through exploit kits on infected websites and emails via infected MS Office and ZIP file attachments. The ransomware seeks to encrypt any files it can find, usually with a “.locky” extension (newer variants use the .zepto, .thot and .zzzzz extensions), before demanding payment in Bitcoin.
Carl Leonard, Principal Security Analyst at Forcepoint: