Security & RansomwarePublished December 6, 2016

What Is Ransomware and How Locky Spread So Fast

A look at how one of this year's most widespread ransomware campaigns tricked so many businesses.

Locky is a ransomware family that spread aggressively this year, primarily through email attachments disguised as invoices or shipping documents. Once opened, a macro embedded in the attached Word document would silently download and run the actual ransomware payload, encrypting files across the victim's system and any connected network drives.

What made Locky so effective wasn't technical sophistication — it was volume and social engineering. Millions of emails were sent out, relying on the simple fact that some percentage of recipients will open an attachment that looks like a legitimate business document, especially one implying they owe money or are expecting a delivery.

Disabling macros by default in Office documents, combined with staff training not to enable them just because a document asks, closes off the most common infection path this particular threat relies on.

Prefer to have this handled for you?

Our team can take care of this and everything else on your IT plate — no obligation to find out how.