In a constant game of cat and mouse, the perpetrators behind Locky ransomware have updated their arsenal yet again with a new tactic—using Windows Scripting File (WSF) for the arrival method. WSF is a file type that allows the combination of multiple scripting languages within a single file. Leveraging WSF pose challenges in detection and analysis, as traditional endpoint solutions scan and filter files based on their list of monitored files. Since WSF is not commonly associated with ransomware routines, this creates a window of exposure and can possibly pass off as a non-malicious file. This was reportedly seen in Cerber’s email campaign last May. Possibly, Locky is possibly following suit to Cerber’s tactic since this is an effective tactic in bypassing security measures like sandbox and blacklisting technologies.
Post from: Trendlabs Security Intelligence Blog – by Trend Micro
New Locky Ransomware Spotted in the Brazilian Underground Market, Uses Windows Script Files