On February 16, 2016, PhishMes Intelligence team identified a number of large sets of emails delivering Word documents containing macro scripts used to download a malware payload. This malware delivery technique has been ubiquitous among many threat actors over the past year but has been most prolifically used by threat actors delivering the Dridex financial crimes trojan. The malware ultimately delivered by these messages was a new encryption ransomware referring to itself as Locky. The similarity of the messages and the OfficeMacro documents used to deliver this encryption ransomware is striking. One set of documents broke from the exclusive use of Visual Basic scripting to leverage a small. PowerShell script to facilitate the download and execution of the malware.”]
Source: https://cofense.com/locky-a-new-encryption-ransomware-borrowing-ideas-from-the-best/

