Experts at Trustwave observed a new massive spam campaign that was sending a JavaScript attachment that downloads Locky ransomware. Spam campaign aiming to spread malware has represented 18 percent of total spam in the last weeks. The threat actors simply changed tactic and malware, in the case os Dridex they used email attachment disguised as an invoice, typically documents embedding malicious macro. These campaigns are coming from the same botnet responsible for previously spammed documents with malicious macros which downloaded the DrideX trojan.”]
Source: http://securityaffairs.co/wordpress/45273/cyber-crime/locky-ransomware-spam-campaign.html