Skip to content

Malware

Locky

Locky is a high profile ransomware family that first appeared in early 2016 and was observed being active until end of 2017.

Locky is a Windows malware family operated by TA505.

Background

Locky is a prominent ransomware family that surfaced in early 2016 and remained active through the end of 2017. After encrypting files on a compromised machine, it demands payment to restore them. Early builds appended a .locky extension to encrypted files, while later variants used the .lukitus extension. Ransom demands are denominated in BTC and vary depending on the operator.


Source: Malpedia (Fraunhofer FKIE).