ZeroHour

Search: “Locky”

7 items

Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX

Unit 42 reports the Afraidgate campaign switched from Nuclear EK delivering Locky to Angler EK delivering CryptXXX via the Bedep downloader.

Unit 42 reported that the Afraidgate campaign, which uses gates registered through FreeDNS at afraid.org, switched in mid-April 2016 from Nuclear EK distributing Locky ransomware to Angler EK distributing CryptXXX. The Angler/Bedep/CryptXXX combination also spread from the pseudo-Darkleech campaign, with Bedep acting as a fileless, memory-resident downloader that also installs click-fraud malware. Recent Bedep updates detect virtual machines and alter behavior, complicating analyst investigation. Unit 42 published gate, EK, and post-infection indicators including gate IP 185.118.164.42 and associated domains.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild

"Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware

Unit 42 profiles the Blank Slate malspam campaign: blank emails with double-zipped attachments delivering Cerber ransomware while cycling abused hosting provider domains.

The Blank Slate campaign sends empty emails containing double-zipped archives with macro-enabled Word documents or JavaScript files that launch PowerShell to download ransomware, primarily Cerber, and occasionally Sage 2.0 or Locky. Unit 42 observed 555 campaign domains over seven months, with actors repeatedly registering new domains and cycling abuse of legitimate hosting providers after takedowns. In a five-day January-February 2017 window, at least eight domains across seven IP addresses were observed hosting Cerber payloads.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild1