Talos has observed three distinct spam campaigns distributing the newest version of Locky ransomware. This comes after a seeming vacation for Locky for around two weeks. The characteristics of the malware campaigns that seem to correlate with the Affiliate ID associated with the Locky binaries that are delivered by each campaign. We will summarize all Indicators of Compromise (IOCs) at the end of this post. In the samples we analyzed, PUMPKIN showed up in 37 separate instances. This is a timely reference with Halloween approaching.”]
Source: https://blog.talosintelligence.com/2016/10/pumpkin-locky.html