A new Locky Ransomware variant has been spotted by researchers at Cyren, it uses DLLs for distribution. The new strain of Locky is delivered via spam campaigns, each malicious email includes a ZIP-archived JavaScript. The downloader script works in a way similar to other strain of the Locky ransomware, the downloaded files are decrypted and saved in the Windows Temp directory, but differently from the past, the malicious payload is DLL file instead a.EXE. The DLL library is loaded using rundll32.exe.”]
Source: https://securityaffairs.co/wordpress/50669/malware/new-locky-ransomware-dlls.html

