After a long absence, the Locky Ransomware is back even stronger and is once again hitting victims through a spam campaign containing malicious documents.

According to researchers, the new wave of spam consists of deceptive emails that appear to contain payment receipts, as their subject lines suggest. “Receipt 425”, “Payment Receipt 2424”, “Payment 1637” are some of the sample email titles, based on the samples that have been detected.
The attachments contained in these emails are in PDF format and have random names (e.g. P72732.pdf), without revealing the content of the files and thus increasing the curiosity of the users. After users download and run the attached PDF, they are then asked to open an embedded Word document.
If they open this file, a pop-up window appears informing them that the document is protected and in order to view its contents they must activate a macro command.
The exploitation of Microsoft macros by attackers to spread malware is a tactic often followed by cybercriminals. As it follows, activating this macro will unleash the Locky Ransomware.
The Locky binary is downloaded, decrypted, and saved to %Temp%\redchip2.exe. The file is then executed, rapidly encrypting files on the computer.

Files encrypted by Locky carry the .OSIRIS extension, so they are easy to spot.
When the file encryption is complete, the following message appears informing victims that they have been infected. “All your files are encrypted with RSA-2048 and AES-128 encryption. […] Decryption of your files is only possible with a private key and the decryption program located on our secret server,” the message states.
The victim will then have to download and install Tor and after going to a specific address, they will have to pay Bitcoins in exchange for the decryption key.
The bad news? There is currently no free decryption tool available for Locky victims, so if you get infected you will either have to say goodbye to your files or pay, which is not recommended under any circumstances. Security experts advise victims to keep their encrypted files in case a working decryption key is found.
📧
Subscribe to the SecNews Newsletter
