Skip to main content
  1. Home
  2. Computing
  3. News

‘Locky’ ransomware harnesses the power of Microsoft Word to trick you into paying

Add as a preferred source on Google

Ransomware is a form of malware that’s more annoying than usual both because it revokes access to your computer, and because it then has the nerve to charge you money in order to reverse the lockout. A new type of ransomware, called Locky, appears to deceive users by taking after banking software Dridex.

In a typical Locky attack, victims are emailed a Microsoft Word document disguised as an invoice that requires that a macro app be executed from within the word processor. By default, macros are disabled by Microsoft. If you happen to have enabled them yourself, though, a macro will open from within Word and download Locky to your computer, explained Palo Alto Networks in a blog post earlier this week.

Recommended Videos

Because of the similarity to a process used by Dridex, many reports are assuming that the developer behind Locky bears some affiliation with the banking software developer “due to similar styles of distribution, overlapping file names, and an absence of campaigns from this particularly aggressive affiliate coinciding with the initial emergence of Locky,” Palo Alto stated.

The way ransomware works is that files on the computer are usually encrypted at the user’s expense, literally, as the malicious software will take control of your personal data and then charge a fee for you to regain access.

It appears the coders behind Locky were planning an attack on a colossal scale. In fact, Palo Alto Networks claims to have uncovered 400,000 sessions that take advantage of the Bartallex macro application used by the ransomware in question.

Unlike other ransomware, Locky’s command-and-control infrastructure tries to employ a key exchange in memory prior to file encryption. Notably, PC World states that this could serve as a weak point for the ransomware.

“This is interesting, as most ransomware generates a random encryption key locally on the victim host and then transmits an encrypted copy to attacker infrastructure,” Palo Alto’s post explains. “This also presents an actionable strategy for mitigating this generation of Locky by disrupting associated” command-and-control networks.

Kevin Beaumont, who wrote a Medium post about the ransomware, points out that files affected by a Locky attack are, quite logically, labeled with a “.locky” extension.

Beaumont adds that for those users affected by Locky within an organization, “You will likely have to rebuild their PC from scratch.

Gabe Carey
A freelancer for Digital Trends, Gabe Carey has been covering the intersection of video games and technology since he was 16…
Dell XPS 14 (DA14260) Review: Dell’s classic Windows laptop returns, and it’s hard to put down
The icon returns, and shows why it's still relevant
Dell XPS 14 Review: Featured

Quick take

Dell’s XPS line has always carried a certain weight. It is one of those Windows laptop families that people recognize even if they don’t follow laptops too closely. Clean design built with premium materials, sharp displays, and high-end hardware. The Dell XPS 14 DA14260 continues that legacy. 

Read more
Samsung’s secret AI chip could finally cool down Exynos phones
Samsung's GAIA AI chip is landing in laptops first, but its shared DNA with Exynos hints at a real fix for phones down the line.
Samsung Exynos chip illustration.

If you've ever owned an Exynos-powered Galaxy phone, you already know the drill: heavy tasks like capturing back-to-back pictures or photos for a while, heavy gaming, or rendering videos turn your device into a hand warmer. 

In such a situation, the battery bar drops faster than usual as well. Turns out, Samsung might be working on the fix, and it's coming in a way nobody expected.

Read more
Buying a monitor? This Mac app can expose problems before the return window closes
Your new monitor may look perfect, but it doesn't hurt to double check.
Screen Test v1.1

Making a brand-new tech purchase doesn't always carry the guarantee of a perfectly functioning unit. But a tiny Mac app called Screen Test can help you find a defect before it gets too late. Screen Test (version 1.1) is a native macOS utility containing more than 25 patterns and diagnostic tools for evaluating built-in and external displays. It can help reveal dead or stuck pixels, backlight bleeding, and other issues. The app works completely offline, so you don't have to rely on browser tabs or an internet connection.

Every pixel gets scrutinized

Read more