.ODIN

ODIN File

Locky Ransomware Encrypted File (.odin variant)
Ask a question
QUICK ANSWER

An .odin file is a document, photo, database or other file that has been encrypted by the Locky ransomware. Locky started appending .odin to the files it locked in September 2016, renaming each one to a random hexadecimal string. You cannot open the file normally because its contents are scrambled with AES-128 and RSA-2048 encryption, and there is no free decryptor. The practical fix is to remove the malware and restore the originals from a clean backup or a shadow copy if one survived.

Developer: Locky ransomware operators (unknown criminal group) Category: Encoded Files MIME: application/octet-stream
OPENS ON Windows
Related: .CRYPT · .SDOC · .AXX · .REM

On this page

19k+ extensions indexed
Last reviewed Jun 18, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the ODIN file format?

An .odin file is a personal file that has been encrypted by the Locky ransomware. Locky is a Windows malware family that first appeared in early 2016 and locks documents, photos, databases and archives, then demands payment for their return. Around September 2016 the operators switched the extension they appended from .zepto to .odin, naming the variant after the Norse god. Researchers at Fortinet found the .odin code was 98-99% identical to the earlier .zepto build, so it is the same malware wearing a new label.

When Locky runs, it scans for roughly 400 file types, encrypts each one with AES-128, and locks the AES key inside RSA-2048 encryption. It then renames every file to a hexadecimal identifier such as 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin, discarding the original name. It also deletes Windows Shadow Volume Copies and drops ransom notes named _HOWDO_text.html and _HOWDO_text.bmp. Finding .odin files means the computer was infected, not that you own an unusual format.

Security & safety

RISK: HIGH

The presence of .odin files means the computer was hit by active ransomware. The .odin files themselves are inert encrypted data and cannot execute, but they signal that Locky ran on the system, deleted shadow copies and may still be present. Never pay the ransom without expert advice, and treat the machine as compromised until it is fully cleaned and, ideally, wiped and rebuilt from a trusted backup.

Format details

in a nutshell
FULL NAMELocky Ransomware Encrypted File (.odin variant)aka Odin File Extension Ransomware, Odin virus
DEVELOPERLocky ransomware operators (unknown criminal group)since September 2016
MIME TYPEapplication/octet-stream
TYPEEncrypted binary (malware output)
This extension is also used by…
  • Samsung Odin firmware package - The Odin flashing tool for Samsung Galaxy devices uses firmware files, but those are typically .tar or .tar.md5 archives rather than a .odin extension. Unrelated to the ransomware.
  • ODIN application data - A handful of niche applications have used .odin for internal data or backup files. These are legitimate and unrelated to Locky.

Programs that open ODIN files

Windows4 apps
Malwarebytes Freemium Run a full scan to detect and remove the Locky infection before attempting any recovery, since the encrypted .odin files themselves cannot be opened.
Emsisoft Anti-Malware Paid Scan the machine to clean out the ransomware, then check Emsisoft's decryptor catalog to confirm whether any tool covers your variant (none exists for Locky .odin).
Windows File Recovery / Shadow Explorer Free Browse Volume Shadow Copies to restore earlier unencrypted versions of the files, though Locky usually deletes these.
ID Ransomware Free Upload a ransom note and an .odin sample to confirm the exact ransomware family and whether any decryption is currently possible.

Technical details

deep spec
EncodingAES-128 (ECB mode) file encryption with the AES key protected by RSA-2048
Byte orderN/A (encrypted ciphertext)
ContainerNone; the original file is overwritten in place as raw ciphertext with a renamed filename
EncryptionRSA-2048 + AES-128. The AES session keys are generated server-side by the attacker's command-and-control infrastructure, so the private key needed for decryption never stays on the victim machine.
Typical sizeRoughly the same size as the original encrypted file
StructureThe plaintext of a targeted document, image, database or archive is replaced by AES-128 ciphertext. The file is then renamed to a hexadecimal identifier of the form [8]-[4]-[4]-[4]-[12] followed by the .odin extension (for example 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin). The original name and extension are not preserved on disk.
PlatformsWindows
NotesLocky's .odin variant targets roughly 400 to 460 file types across documents, databases, images and archives. It deletes Windows Shadow Volume Copies to block local recovery and drops ransom notes named _HOWDO_text.html, _HOWDO_text.bmp and _[2-digit-number]_HOWDO_text.html. It is delivered by spam email carrying WSF/JS script attachments or macro-laden Office documents that download an encrypted DLL and run it via rundll32.exe. Despite the name, victims are infected by Locky using the .odin extension, not a separate 'Odin' malware family; code comparison shows a 98-99% match with the earlier .zepto variant.
ReleasedSeptember 2016

ODIN conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with ODIN files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about ODIN files.

Frequently asked questions

How do I open an .odin file?
You cannot open it in the normal sense. The file is encrypted by Locky ransomware and its contents are scrambled. The only way to get usable data back is to restore the original file from a backup or shadow copy after removing the malware.
Can I decrypt .odin files for free?
No. There is no free or public decryptor for the Locky .odin variant. The AES key is protected by RSA-2048 and held on the attackers' servers, so decryption without that private key is not feasible.
Is the .odin file itself dangerous?
The encrypted .odin file is inert and cannot run or spread on its own. The danger is that its existence proves Locky ransomware executed on the system, so the machine should be scanned and cleaned right away.
Should I pay the ransom to recover my .odin files?
Security experts advise against paying. Payment funds criminal operations and there is no guarantee you receive a working key. Restoring from backup is the recommended path.
Why were my files renamed to random characters?
Locky renames each encrypted file to a hexadecimal identifier such as 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin, discarding the original name. This is normal behavior for this variant and makes it harder to tell which file was which.
Is Odin a separate ransomware from Locky?
No. Despite the name, .odin files are produced by Locky using the .odin extension. Code analysis showed a 98-99% match with the earlier .zepto Locky variant, confirming it is the same malware family.

References

1Wikipedia - Lockyen.wikipedia.org
2Bleeping Computer - Locky Ransomware now uses the .ODIN extensionwww.bleepingcomputer.com

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.BINCD/DVD Disc Image (BIN/CUE)
3.MDMarkdown Document
4.RPMSGRestricted Permission Message
5.PARTPartial Download File
6.CRDOWNLOADChrome Partial Download File
7.NOMEDIAAndroid No-Media Marker File
8.PRDXSoftMaker Presentations Document
9.PRO6XProPresenter 6 Bundle File
10.SWFSmall Web Format (Shockwave Flash)

Related extensions

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z