Old Locky Ransomware Resurfacing Using PDFs—Alert Your Employees

Robinson+Cole Data Privacy + Security Insider
Contact

We have previously reported on the vicious ransomware Locky and how it victimized companies throughout 2016 [View previous posts here, here, and here].

Although Locky quieted down in late 2016, according to researchers at Cisco Talos, Locky is perking up again in 2017 in a major way. Only this time, instead of using phishing email schemes that used attached Word documents, the attackers are now using PDF files. When the user opens the PDF, the PDF contains an embedded Word document, which the user is asked to open. When the user opens the Word document, the user is told that the document is protected, and that macros need to be enabled to view the document. When the macros are installed by the user, the ransomware is downloaded.

The scary thing about this new delivery method is that most employees now know not to open attachments or click links in emails from unknown individuals. But by using the PDF format, employees may not be as suspicious, and may open the PDF. Then when it looks like the document is protected (which could easily be mistaken as “encrypted”), the user believes s/he is using special precaution and abiding by good security measures. But the user is being duped into downloading the ransomware by thinking s/he is doing the right thing.

This is very frustrating for those of us who are working hard to educate employees on good security practices and protect them and companies from becoming victims.

The hackers will continue to get more and more creative, and keeping up with their creativity is exhausting. In this case, let your employees know about this new campaign, and empower them to ask questions, and to be vigilant and highly suspicious.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide