Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 13:44:29 UTC Home > List all groups > List all tools > List all groups using tool Locky Tool: Locky Names Locky Category Malware Type Ransomware Description Locky is a high profile ransomware family that first appeared in early 2016 and was observed being active until end of 2017. It encrypts files on the victim system and asks for ransom in order to have back original files. In its first version it added a .locky extension to the encrypted files, and in recent versions it added the .lukitus extension. The ransom amount is defined in BTC and depends on the actor. Information Malpedia AlienVault OTX Last change to this tool card: 14 May 2020 Download this tool card in JSON format All groups using tool Locky Changed Name Country Observed APT groups https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5142b595-a174-46d6-984f-838a926e3799 Page 1 of 2 TA505, Graceful Spider, Gold Evergreen 2006-Nov 2022 Other groups   Dungeon Spider 2016-Feb 2018   2 groups listed (1 APT, 1 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5142b595-a174-46d6-984f-838a926e3799 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5142b595-a174-46d6-984f-838a926e3799 Page 2 of 2