Netskope Threat Labs

Locky

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Locky is ransomware that spread through enormous malicious email campaigns from 2016 to 2018, at times delivering hundreds of thousands of infected messages per hour. Its attachments relied on macros and script downloads, and its operators rotated infrastructure constantly to survive disruption. The family's campaigns fed the same criminal ecosystem as Dridex, and its volume set records that shaped modern email security practices.

First seen
February 2022
Last seen
October 2026
Alert Name
Binary.Ransomware.Locky
Document-Word.Ransomware.Locky
Gen:Heur.Locky.1
Gen:Heur.Locky.2
Gen:Variant.Locky.12
Gen:Variant.Locky.7
Gen:Variant.Ransom.Locky.103
Gen:Variant.Ransom.Locky.112
Gen:Variant.Ransom.Locky.135
Gen:Variant.Ransom.Locky.140