About stevenmbrun
- Member Since: 16-06-2022
Description
Why is Locky so dangerous?
In our last post we discussed the evolution of ransomware, and we covered some of the reasons why ransomware was spreading so quickly right now. In this post we’ll go into more detail on that, with emphasis on what makes Locky so dangerous to potential victims.
Locky was identified in mid-February, and within 2 weeks had become the second most prevalent version of ransomware around the world. Locky has been spread primarily through app, spam email with Word attachments. The attachment contains a malicious macro and is usually presented as an invoice. When the user attempts to open the Word document, the text is scrambled and the user is instructed to enable macros. Enabling the macros will allow the virus to contact a remote server, download an executable, and run the file. This executable is the Locky ransomware that will execute immediate and begin to encrypt the files on the computer and unmapped network shares.
Locky has also used .js and .zip file attachments to infect PCs.
Locky uses the AES encryption algorithm to encrypt files. It will not encrypt certain types of system files, but it will encrypt all user data, which it identifies based on extension. It also changes the file names on encrypted files, making it more difficult to restore data. Locky will also delete all Shadow Volume copies of data so that the user cannot use those files to avoid paying the ransom. Finally, Locky creates a ransom note and copies it to every directory where files have been encrypted. The ransom note includes links to a decrypter page, which provides instructions on “how to buy Locky decrypter.”
Security experts say there are several reasons why Locky is spreading so quickly:
Information gleaned from social media research has been used to customize the email, making it easier to gain the victim’s trust. This research is automated with advanced scraping software that scans profiles and then delivers the malicious email messages to victims.
It appears that Locky is being distributed by the criminals associated with Dridex banking trojan, which has been a dominant threat for over a year. This means the criminals are experienced with malware and have an established botnet infrastructure and spam operation to manage and distribute the Locky attacks.
Locky uses both AES-128 and RSA encryption software. There is currently no way to decrypt Locky encrypted files without the decrypter key.
Locky developers have the ability to change domains every day. This means that the public cannot block Locky simply by blocking the domains used to host the software.
Rather than targeting a single enterprise for a large ransom, the Locky attacks have pursued smaller ransoms on a global basis. Organizations of all sizes are targets.
Like all ransomware, protection from Locky requires a comprehensive security and storage strategy. Network firewalls, email security and web filtering can prevent spam from getting through to the users document made <a href="https://apps.apple.com/us/app/scanner-app-scan-pdf-docs-id/id1495971405">home office document scanner</a> and will prevent downloads of compromised attachments. A good backup system and disaster recovery plan will help you restore your data in the event that you are compromised.
For more information on ransomware, follow our blog series. For more on Barracuda solutions that can help protect you from attacks like Locky, visit these product sites.
Get more:
<a href="https://stevenmbrun.whotrades.com/">ShopSavvy Barcode Scanner SDK Update (2)</a>
<a href="https://myapple.pl/users/394338-steven-brun">ShopSavvy 4 on Android is LIVE! Download NOW!</a>
Listings
No listings found.