Locky, one of the most dangerous and widespread ransomware families today, along with Cerber and CryptXXX, has undergone yet another update, this time dropping offline support and adding a new extension for encrypted files.
Back in mid-July, the criminal group behind the Locky ransomware had released a version of ransomware that could operate without an Internet connection, in a so-called "offline mode."
This Locky version was distributed via five spam botnets. According to a report from Avira, three of these botnets have now started distributing a Locky variant that leaves offline support, connects to an online C&C server, just like the other Locky versions.
“Maybe it didn’t work as well as expected,” said Moritz Kroll, a malware expert at Avira Protection Labs. “Or they were just surprised by the number of successful infections.”
Additionally, security researcher @dvk01uk says that recent Locky variants now append the .ODIN file extension to encrypted files. Previously, Locky had used .LOCKY (from which it got its name) and .ZEPTO. Users infected with this newer Locky variant should be aware that it is still Locky and not Odin ransomware.
Additionally, the infection method. Previous versions relied on victims to download malicious ZIP files received via spam emails. These files contained WSF or JS files, which, when executed, would download and install a malicious EXE file, the actual ransomware.
The researcher stated on Twitter that for more than a month, starting on August 24, these WSF and JS files were downloading a DLL file instead of the EXE installer program, which they used to deploy the ransomware.
Small changes like these may seem silly and useless, but they can help crooks evade security scanners and antivirus solutions!

