A new Locky Ransomware variant was discovered by security researcher Derek Knight and then quickly followed by Stormshield malware analyst coldshell that switches to the.ykcol extension for encrypted files. This variant is currently being distributed via spam emails that have a subject line of Status of invoice, which contain a 7zip, or 7z, attachment. This is probably being done to bypass more stringent filters put in place recently by Gmail and other mail services. At this time it is still not possible to decrypt the Locky ransomware for free.
Source: https://www.bleepingcomputer.com/news/security/locky-ransomware-switches-to-the-ykcol-extension-for-encrypted-files/