October 24, 2017 By Shane Schick 2 min read

The cybercriminals behind the Locky ransomware attacks are upping their game by using an application linking feature in Windows to hit even more victims without being immediately noticed.

According to an advisory from the Internet Storm Center, the new variant of Locky ransomware exploits Microsoft’s Dynamic Data Exchange (DDE), a Windows feature that facilitates the electronic transfer of Office files using shared memory and data.

Locky Adopts DDE Hijacking Tactics

In keeping with similar approaches, the fraudsters created phony invoices laden with malicious links and distributed them via the Necurs spambot. Because they used DDE, the threat actors did not have to employ macros to download malware from a remote server.

The Locky malware self-destructs once the ransomware attacks are successful, at which point the cybercriminals demand payment in the form of bitcoin. Besides DDE, according to SecurityWeek, Locky is being disseminated via Visual Basic scripts and archived in formats such as RAR containing VBS, JSE and JS files. The variety of techniques makes the threat much more difficult for security experts to track.

DDE is hardly a new feature from Microsoft, dating back to the late 1980s. BankInfoSecurity pointed out that potential dangers associated with DDE include the ability for cybercriminals to instantly execute links in a document once a victim opens it.

Microsoft offered an alternative several years ago called Object Linking and Embedding (OLE) but continues to support DDE because it is a part of legacy versions of Office products. Though the company has been informed about the risks, it maintained that the issues with DDE do not technically represent a bug.

Predicting Locky Ransomware’s Next Move

Threatpost reported that the only way to avoid the issue entirely is to go into the settings of Office applications and ensure that they don’t automatically update links. Given that DDE is a legitimate feature, however, it is less likely to be stopped by traditional antivirus or security scanning systems.

Ransomware attacks from Locky will likely take many forms and target widely used applications such as Microsoft Word. Hijacking DDE may just be a taste of what’s yet to come.

More from

Hive0137 and AI-supplemented malware distribution

12 min read - IBM X-Force tracks dozens of threat actor groups. One group in particular, tracked by X-Force as Hive0137, has been a highly active malware distributor since at least October 2023. Nominated by X-Force as having the “Most Complex Infection Chain” in a campaign in 2023, Hive0137 campaigns deliver DarkGate, NetSupport, T34-Loader and Pikabot malware payloads, some of which are likely used for initial access in ransomware attacks. The crypters used in the infection chains also suggest a close relationship with former…

Unveiling the latest banking trojan threats in LATAM

9 min read - This post was made possible through the research contributions of Amir Gendler.In our most recent research in the Latin American (LATAM) region, we at IBM Security Lab have observed a surge in campaigns linked with malicious Chrome extensions. These campaigns primarily target Latin America, with a particular emphasis on its financial institutions.In this blog post, we’ll shed light on the group responsible for disseminating this campaign. We’ll delve into the method of web injects and Man in the Browser, and…

Crisis communication: What NOT to do

4 min read - Read the 1st blog in this series, Cybersecurity crisis communication: What to doWhen an organization experiences a cyberattack, tensions are high, customers are concerned and the business is typically not operating at full capacity. Every move you make at this point makes a difference to your company’s future, and even a seemingly small mistake can cause permanent reputational damage.Because of the stress and many moving parts that are involved, businesses often fall short when it comes to communication in a crisis.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today