{"id":52587,"date":"2016-02-17T21:06:38","date_gmt":"2016-02-17T21:06:38","guid":{"rendered":"https:\/\/www.pcmatic.com\/blog\/?p=52587"},"modified":"2016-02-22T21:26:46","modified_gmt":"2016-02-22T21:26:46","slug":"actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware","status":"publish","type":"post","link":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/","title":{"rendered":"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware"},"content":{"rendered":"<p>Recent reports have indicated that the actors behind Dridex, originally a banking Trojan distributor, have switched tactics, and are now heavily pushing out a new ransomware called Locky.<\/p>\n<p>The current method of distribution is via a spam email, which contains a Word document. Additional reports have stated that it is being distributed via the Neutrino Exploit Kit.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-52590\" src=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-300x30.png\" alt=\"dodi\" width=\"550\" height=\"55\" srcset=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-300x30.png 300w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-768x76.png 768w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi.png 845w\" sizes=\"(max-width: 550px) 100vw, 550px\" \/><\/p>\n<p><i>Note, the file name may be different for every email sent, but the file will always be a Word document.<\/i><\/p>\n<p>If you open the email, you\u2019ll see an alert by Word, which warns you that the document contains a macro. Macros allow users to \u201ccode\u201d specific procedures into the document, to help automate or repeat specific tasks.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-52591\" src=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-1-300x36.png\" alt=\"dodi 1\" width=\"550\" height=\"66\" srcset=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-1-300x36.png 300w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-1.png 497w\" sizes=\"(max-width: 550px) 100vw, 550px\" \/><\/p>\n<p>However, in the case of Locky, it is used to install the malware on the machine.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone wp-image-52592\" src=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-2-300x149.png\" alt=\"dodi 2\" width=\"551\" height=\"274\" srcset=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-2-300x149.png 300w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-2-768x382.png 768w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-2-1024x509.png 1024w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-2.png 1600w\" sizes=\"(max-width: 551px) 100vw, 551px\" \/><\/p>\n<p><i>This is a screenshot of the actual macro that delivers Locky<\/i>.<\/p>\n<p>If you happen to ignore the alert from Word, and clicked on Enable content, Locky will scan your system for specific files, and will encrypt them, or modify them so that you cannot use them anymore, unless you pay the ransom.<\/p>\n<p>The files it encrypts are commonly found on end users\u2019 machines, such as .doc, .csv, .pdf, .jpg, etc. However, what should be more concerning to enterprise customers is that it will also look for .SQL, .SQLiteDB, and .SQLite3 files, which are associated with databases. Additionally, it looks to encrypt encryption keys (.crt and .key).<\/p>\n<p>Once the malware has been executed, the Desktop wallpaper may change, to show instructions on how to decrypt your files.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-52593\" src=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-3-300x157.png\" alt=\"dodi 3\" width=\"550\" height=\"288\" srcset=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-3-300x157.png 300w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-3-768x401.png 768w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-3-1024x535.png 1024w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-3.png 1233w\" sizes=\"(max-width: 550px) 100vw, 550px\" \/><\/p>\n<p>It will also drop text files that contain the same instructions on how to decrypt your files. These files are named _Locky_recover_instructions.txt.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-52594\" src=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-4-300x182.png\" alt=\"dodi 4\" width=\"550\" height=\"334\" srcset=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-4-300x182.png 300w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-4-768x466.png 768w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-4.png 884w\" sizes=\"(max-width: 550px) 100vw, 550px\" \/><\/p>\n<p>The transaction is all too familiar for many of the other types of ransomware out there. The malware authors have you visit a website, hosted on the TOR network, to provide payment. For Locky, the current amount is .5 BTC, or the equivalent of $209.33.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-52595\" src=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-5-300x139.png\" alt=\"dodi 5\" width=\"552\" height=\"256\" srcset=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-5-300x139.png 300w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-5-768x356.png 768w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-5-1024x475.png 1024w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-5.png 1600w\" sizes=\"(max-width: 552px) 100vw, 552px\" \/><\/p>\n<p><i>Bitcoin site hxxps:\/\/6dtxgqam4crv6rr6.tor2web.org\/728EF3F4A1802521<\/i><\/p>\n<p>We\u2019ve looked into the Bitcoin address, 151xDKSeevSsBYu4oeFczYSb5z7UPY35zv, but currently do not see any transactions.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-52596\" src=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-6-300x102.png\" alt=\"dodi 6\" width=\"550\" height=\"187\" srcset=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-6-300x102.png 300w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-6-768x261.png 768w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-6-1024x348.png 1024w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-6.png 1211w\" sizes=\"(max-width: 550px) 100vw, 550px\" \/><\/p>\n<p>PC Matic users should know that this malware is blocked, and cannot be executed on machines protected with Super Shield.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-52597\" src=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-7-300x63.png\" alt=\"dodi 7\" width=\"552\" height=\"116\" srcset=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-7-300x63.png 300w, https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/dodi-7.png 654w\" sizes=\"(max-width: 552px) 100vw, 552px\" \/><\/p>\n<p>You can read additional information about Locky Ransomware <a href=\"https:\/\/blog.knowbe4.com\/its-here.-new-ransomware-hidden-in-infected-word-files\" target=\"_blank\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recent reports have indicated that the actors behind Dridex, originally a banking Trojan distributor, have switched tactics, and are now heavily pushing out a new ransomware called Locky. The current method of distribution is via a spam email, which contains a Word document. Additional reports have stated that it is being distributed via the Neutrino [&hellip;]<\/p>\n","protected":false},"author":55,"featured_media":66012,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4851,4522],"tags":[4900,4363,4882],"class_list":["post-52587","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-research-team","category-pc-safety-2","tag-locky","tag-ransomware","tag-spam"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Actors behind Dridex launch another spam campaign, delivering Locky Ransomware<\/title>\n<meta name=\"description\" content=\"Recent reports have indicated that the actors behind Dridex, originally a banking Trojan distributor, have switched tactics, and are now heavily pushing\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware\" \/>\n<meta property=\"og:description\" content=\"Recent reports have indicated that the actors behind Dridex, originally a banking Trojan distributor, have switched tactics, and are now heavily pushing\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"PC Matic Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/pcmatic\" \/>\n<meta property=\"article:published_time\" content=\"2016-02-17T21:06:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-02-22T21:26:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/pcmatic-fallback.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Dodi Glenn\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@pcmatic\" \/>\n<meta name=\"twitter:site\" content=\"@pcmatic\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Dodi Glenn\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/\"},\"author\":{\"name\":\"Dodi Glenn\",\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/#\\\/schema\\\/person\\\/48ddc92048489e51436331f82e991e37\"},\"headline\":\"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware\",\"datePublished\":\"2016-02-17T21:06:38+00:00\",\"dateModified\":\"2016-02-22T21:26:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/\"},\"wordCount\":395,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/wp-content\\\/uploads\\\/pcmatic-fallback.png\",\"keywords\":[\"Locky\",\"ransomware\",\"Spam\"],\"articleSection\":[\"Malware Research Team\",\"PC Safety\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/\",\"url\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/\",\"name\":\"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/wp-content\\\/uploads\\\/pcmatic-fallback.png\",\"datePublished\":\"2016-02-17T21:06:38+00:00\",\"dateModified\":\"2016-02-22T21:26:46+00:00\",\"description\":\"Recent reports have indicated that the actors behind Dridex, originally a banking Trojan distributor, have switched tactics, and are now heavily pushing\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/wp-content\\\/uploads\\\/pcmatic-fallback.png\",\"contentUrl\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/wp-content\\\/uploads\\\/pcmatic-fallback.png\",\"width\":1920,\"height\":1080},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/\",\"name\":\"PC Matic Blog\",\"description\":\"Tech Tips and Tricks\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/#organization\",\"name\":\"PC Matic - Top Antivirus Company in the USA.\",\"url\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/techtalk.pcmatic.com\\\/wp-content\\\/uploads\\\/PC-MaticLogo-e1472689639222.png\",\"contentUrl\":\"https:\\\/\\\/techtalk.pcmatic.com\\\/wp-content\\\/uploads\\\/PC-MaticLogo-e1472689639222.png\",\"width\":1535,\"height\":483,\"caption\":\"PC Matic - Top Antivirus Company in the USA.\"},\"image\":{\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/pcmatic\",\"https:\\\/\\\/x.com\\\/pcmatic\",\"https:\\\/\\\/www.instagram.com\\\/pcmaticusa\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/pcmatic\",\"https:\\\/\\\/www.youtube.com\\\/c\\\/PCMaticVideo\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/#\\\/schema\\\/person\\\/48ddc92048489e51436331f82e991e37\",\"name\":\"Dodi Glenn\",\"url\":\"https:\\\/\\\/www.pcmatic.com\\\/blog\\\/author\\\/dodig\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware","description":"Recent reports have indicated that the actors behind Dridex, originally a banking Trojan distributor, have switched tactics, and are now heavily pushing","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/","og_locale":"en_US","og_type":"article","og_title":"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware","og_description":"Recent reports have indicated that the actors behind Dridex, originally a banking Trojan distributor, have switched tactics, and are now heavily pushing","og_url":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/","og_site_name":"PC Matic Blog","article_publisher":"https:\/\/www.facebook.com\/pcmatic","article_published_time":"2016-02-17T21:06:38+00:00","article_modified_time":"2016-02-22T21:26:46+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/pcmatic-fallback.png","type":"image\/png"}],"author":"Dodi Glenn","twitter_card":"summary_large_image","twitter_creator":"@pcmatic","twitter_site":"@pcmatic","twitter_misc":{"Written by":"Dodi Glenn","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/#article","isPartOf":{"@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/"},"author":{"name":"Dodi Glenn","@id":"https:\/\/www.pcmatic.com\/blog\/#\/schema\/person\/48ddc92048489e51436331f82e991e37"},"headline":"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware","datePublished":"2016-02-17T21:06:38+00:00","dateModified":"2016-02-22T21:26:46+00:00","mainEntityOfPage":{"@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/"},"wordCount":395,"commentCount":0,"publisher":{"@id":"https:\/\/www.pcmatic.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/pcmatic-fallback.png","keywords":["Locky","ransomware","Spam"],"articleSection":["Malware Research Team","PC Safety"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/","url":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/","name":"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware","isPartOf":{"@id":"https:\/\/www.pcmatic.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/pcmatic-fallback.png","datePublished":"2016-02-17T21:06:38+00:00","dateModified":"2016-02-22T21:26:46+00:00","description":"Recent reports have indicated that the actors behind Dridex, originally a banking Trojan distributor, have switched tactics, and are now heavily pushing","breadcrumb":{"@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/#primaryimage","url":"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/pcmatic-fallback.png","contentUrl":"https:\/\/www.pcmatic.com\/blog\/wp-content\/uploads\/pcmatic-fallback.png","width":1920,"height":1080},{"@type":"BreadcrumbList","@id":"https:\/\/www.pcmatic.com\/blog\/actors-behind-dridex-launch-another-spam-campaign-delivering-locky-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.pcmatic.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Actors behind Dridex launch another spam campaign, delivering Locky Ransomware"}]},{"@type":"WebSite","@id":"https:\/\/www.pcmatic.com\/blog\/#website","url":"https:\/\/www.pcmatic.com\/blog\/","name":"PC Matic Blog","description":"Tech Tips and Tricks","publisher":{"@id":"https:\/\/www.pcmatic.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.pcmatic.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.pcmatic.com\/blog\/#organization","name":"PC Matic - Top Antivirus Company in the USA.","url":"https:\/\/www.pcmatic.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.pcmatic.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/techtalk.pcmatic.com\/wp-content\/uploads\/PC-MaticLogo-e1472689639222.png","contentUrl":"https:\/\/techtalk.pcmatic.com\/wp-content\/uploads\/PC-MaticLogo-e1472689639222.png","width":1535,"height":483,"caption":"PC Matic - Top Antivirus Company in the USA."},"image":{"@id":"https:\/\/www.pcmatic.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/pcmatic","https:\/\/x.com\/pcmatic","https:\/\/www.instagram.com\/pcmaticusa\/","https:\/\/www.linkedin.com\/company\/pcmatic","https:\/\/www.youtube.com\/c\/PCMaticVideo"]},{"@type":"Person","@id":"https:\/\/www.pcmatic.com\/blog\/#\/schema\/person\/48ddc92048489e51436331f82e991e37","name":"Dodi Glenn","url":"https:\/\/www.pcmatic.com\/blog\/author\/dodig\/"}]}},"_links":{"self":[{"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/posts\/52587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/comments?post=52587"}],"version-history":[{"count":0,"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/posts\/52587\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/media\/66012"}],"wp:attachment":[{"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/media?parent=52587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/categories?post=52587"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pcmatic.com\/blog\/wp-json\/wp\/v2\/tags?post=52587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}