<span id="hs_cos_wrapper_post_body" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text" ><p>&nbsp;</p> <!--more--> <p>Locky is a new ransomware that encrypts a victim's data using AES encryption and then demands .5 bitcoins for the decryption of that data. The malware is currently being distributed via email that contains Word document attachments with malicious macros.</p> <p>The text in the document is scrambled, luring the victim into downloading the macros. Once the victim enables the macros, it downloads an executable from a remote server and executes it, infecting the victim with the ransomware.</p> <p>ThreatSTOP customers are protected from Locky. The ThreatSTOP Shield service blocks the IP addresses used by the attackers.</p></span>