Security Alert! Locky Ransomware on the loose

  • 110
    Shares
locky_ransomware

‘Locky’ is the latest addition to the ransomware family. It has an interesting name and carries the same nastiness. Read more from the post below.

What is the Locky Ransomware?
Locky is a new file-encrypting ransomware malware. It does two things:

  • Encrypts the files it finds in the PC it infects.
  • Changes the extension of the encrypted files to .locky

And as most of us know, the encrypted files can be decrypted only with a key available with the cyber crook and for a price.

Who all are in the red zone?
Locky ransomware is known to target Windows users.

How does it infect a machine?

The ransomware seems to be using different spam email campaigns to spread and infect its target victims.

In one campaign, it’s been noticed that the email seems to be from a popular organization, and asks the user to download an invoice attachment (MS Word doc).

The document contains text that looks incomprehensible or unreadable. And to make the text readable, the user needs to enable ‘macros’.

If the user falls for this trick and enables the ‘macros’, a series of automatic processes is triggered which finally results in installing the Locky Ransomware on the machine.

Once inside the system, the ransomware begins encrypting whatever files it can find.

What happens next?
Once Locky is done encrypting the files, it displays a message to the user on the desktop. The message informs what has happened, and that decrypting the files is only possible by purchasing a private key from the hacker; the cost could be up to ₹ 26,558/- ($400).

What do we suggest?

  • Back up your important files regularly, and have the backup encrypted. This will make sure that the data does not misused by anyone.
  • Do not trust any email that asks you to download an attachment, a software, survey forms or anything that you were not expecting; no matter how professional, urgent, or grand the email may look or sound. If you think the email is genuine, have it verified with the sender over a call or personally.
  • Avoid using your computer with an ‘Administrator’ account unless necessary. Logged in as an administrator and being attacked by a malware can cause irreparable damage to your PC. Always log in as a standard User for day-to-day usage. Here is a post that explains more about why you shouldn’t run as admin?
  • Keep your Windows OS and all other programs/applications up-to-date with the latest security updates/patches. In most cases of ransomware infections, the malware takes advantage of security vulnerabilities present in the user’s system.

How Quick Heal helps?

We have released an update to Quick Heal desktop products that prevents the attack of Locky Ransomware. Besides this, our multilayered defense mechanism helps prevent all types of malware attacks including new ransomware infections.

Email Security blocks emails carrying malicious links and attachments.

Web Security blocks websites containing hidden malware and viruses, and websites designed for phishing attacks.

Advanced DNAScan stops new and unknown malware that can cause the most damage.

Anti-Ransomware stops ransomware from encrypting any data. The feature works in multiple ways to prevent a potential ransomware attack.

  • Scans every downloaded file whose components could become a potential ransomware attack.
  • Analyzes how a program behaves in real-time, so that it can be stopped before it does any damage.
  • Proactive backup prevents data loss even in cases where certain files might get encrypted by a ransomware.
  • Helps user keep a track of files that have gotten encrypted.
  • Alerts user immediately to take a corrective action.
  • Isolates detected ransomware infections; stops them from spreading and doing any damage.

We are keeping a track of the Locky Ransomware and its developments. We will keep you posted in case we come across anything important. Stay safe!

Rajiv Singha

Rajiv Singha

Follow @Singha_Ra

Subscribe
Notify of
guest
46 Comments
Inline Feedbacks
View all comments
RANJEET KUMKAR
RANJEET KUMKAR
4 years ago

Security Alert! is very goods

chunaram334@gmail.com
chunaram334@gmail.com
4 years ago

i like

Swami Sushantananda
Swami Sushantananda
4 years ago

Many thanks for giving me valuable alertness message.

Prodip ghosh
Prodip ghosh
4 years ago

GD

jagbeer
jagbeer
4 years ago

how is rocky….that is various

md khlid raza
md khlid raza
4 years ago

this is safe and secure for our system.
thank’s quick heal

Bharat digwal
Bharat digwal
4 years ago

hii

M P Sharma
M P Sharma
4 years ago

Am happy to be using Quick Heal

srinivas
srinivas
4 years ago

excelent

hardasbhaigojiya@gmail.com
hardasbhaigojiya@gmail.com
4 years ago

LIKE TO QUICKHEAL

Mallikarjun
Mallikarjun
4 years ago

Most Useful for us
Thanks

AmanJaiswal505@gmail.com
AmanJaiswal505@gmail.com
4 years ago

Aman jaiswal

namrata chandel
namrata chandel
4 years ago

dangerous

pamar ajay
pamar ajay
4 years ago

Good softwir

karthikeyan
karthikeyan
4 years ago

good

vivek masih
vivek masih
4 years ago

thanks

Santosh Kumar mehta
Santosh Kumar mehta
4 years ago

Like

Rajesh kumar raj
Rajesh kumar raj
4 years ago

SECURITY ALERT

HIMANSHU GAGAT
HIMANSHU GAGAT
4 years ago

NIC

nadeem
nadeem
4 years ago

this is a great

nadeem
nadeem
4 years ago
Reply to  nadeem

thenks

Awokoya
Awokoya
4 years ago

I love it thanks

RAJPAL SINGH
RAJPAL SINGH
4 years ago

Guardian Netsecure

Santanu Ku.Patra
Santanu Ku.Patra
4 years ago

Hi

AJAY PRATAP
AJAY PRATAP
4 years ago

Thanks. This does help!!

sachin tiwari
sachin tiwari
4 years ago

very good

shuvankar dey
shuvankar dey
4 years ago

good

mukesh
mukesh
4 years ago

nice

hiren vyas
hiren vyas
4 years ago

I have renewed quick heal total securities on line through credit card payment on 29/03/2016 order no. 100699357 transaction no.60892249709 (ICICI BANK) for 1 year payment Rs.1364/- your thanks for renewal email recd .but on my pc renewal are not shown up till now kindly look in to the matter & talk necessary action in this.

C Bhattacharyya
C Bhattacharyya
4 years ago

Start my security

saurah rai
saurah rai
4 years ago

better than all…

sandip Gurav
sandip Gurav
4 years ago

It’s Very Nice, Thanks Quick Heal

santanu mukherjee
santanu mukherjee
4 years ago

I am facing problem with quickheal guardinier. Every day machine hangs when opening, starts from safe mode run virus clean then starting in normal mode.

Now a days it is nightmare to me.

Please do the needful at the earliest.

SAGAR DUTTA
SAGAR DUTTA
4 years ago

Happy to get knowledge

DINESH K MAKWANA
DINESH K MAKWANA
4 years ago

MY QUICK HEAL SECURITY NO WORKING PROPERLY

Asad Khan
Asad Khan
4 years ago

Hi, I have been using quickheal total security for last more than 7 years. I never had a problem, 2 days ago all of a sudden all my files were renamed with .DECRYPT and i figured out it was a ransomware, i was able to quickly restore my computer to an earlier date with Acronis, now the virus has been removed from my computer and all my C: data has restored, but my entire D: & E: data has .DECRYPT, it cannot be used at all, i need these documents badly. Does Quickheal offer any tool for restoring such encrypted… Read more »

mukund.tilak@gmail.com
mukund.tilak@gmail.com
4 years ago

My system has got attacked by Locky & Word, Excel files have been damaged. Will you be able to help me in recovering the same?

Pratibha Agarwal
Pratibha Agarwal
4 years ago

hey i install the guardian net secure bt when i update it the virus protection is automatically disable and my net is not supported it plz help

franklyn
franklyn
4 years ago

is there any way to restore a file which is infected by locky extension by scanning with quick heal

46
0
Would love your thoughts, please comment.x
()
x