Locky

Category: ransomware · Aliases: zepto · Sample count (EMBER 2018): 11 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Locky is a major ransomware family active primarily from 2016 to 2017 that became one of the most prevalent ransomware strains during that period. It encrypts files with RSA-2048 plus AES and appends extensions such as .locky, .zepto, .odin, and .thor across its variants. Locky was distributed at massive scale through the Necurs botnet using malicious Office documents and JavaScript attachments. Its operators retired around 2017, though Locky-derived code influenced subsequent ransomware families.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1566.001 T1486 T1490

Frequently Asked Questions

What is Locky?

Locky is a major ransomware family active primarily from 2016 to 2017 that became one of the most prevalent ransomware strains during that period. It encrypts files with RSA-2048 plus AES and appends extensions such as .locky, .zepto, .odin, and .thor across its variants. Locky was distributed at massive scale through the Necurs botnet using malicious Office documents and JavaScript attachments. Its operators retired around 2017, though Locky-derived code influenced subsequent ransomware families.

How does Locky spread?

Locky spread through massive phishing campaigns using malicious Word, Excel, and JavaScript attachments, peaking in 2016 before declining sharply.

What are the signs of a Locky infection?

Files renamed with .locky, .zepto, .odin, or .aesir extensions, ransom notes named _Locky_recover_instructions.txt, and antivirus references to Locky are diagnostic.

What should I do if I think I have Locky on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/locky.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.