HomeSecurityNecurs Botnet comes back to life, three weeks later!

The Necurs Botnet is back to life, three weeks later!

Three weeks of silence is what we got from the world's largest botnet, which seems to have come back to life and is preparing for new spam and malware campaigns. According to reports from MalwareTech and Proofpoint, the Necurs botnet, one of the largest botnets in the world with 6.1 million bots, had ceased all activity on May 31st, when its main C&C servers were simply shut down.

The Necurs Botnet is back to life, three weeks later!

The Necurs shutdown was immediately felt, and security researchers noticed a drop in Locky ransomware spam email deliveries. Mysteriously, spam messages carrying the Dridex banking trojan also slowed down, which raised the curiosity that Dridex has a separate botnet from the one it operates in.

Now, the same MalwareTech that announced the botnet's downfall has detected new Necurs activity. Security firm AppRiver has also confirmed its findings.

Necurs came to life this Sunday, when the crooks behind the botnet set up new C&C servers and within a short period of time, a large number of bots began connecting to the new backend.

"The fact that bots will not stop conducting DGA 'research' until a C&C server responds with a digitally signed response suggests that the botmasters still have full control of the botnet or someone else holds the private key," explains MalwareTech.

Since the botnet returned, researchers have also seen a resurgence of Locky spam, but with the same samples detected by antivirus on May 31.

Curs-back-to-life-after-three-weeks

MalwareTech says that the Necurs group always starts new campaigns with a new batch of undetected Locky ransomware samples and this looked like the Necurs group simply hit the “Pause/Resume” button on an older campaign.

In the past, cybercriminal groups have been known to take their time, whether it's for maintenance work or upgrading their servers, but usually before a major infrastructure update.

With no new Locky or Dridex malware observed from this botnet, we will have to wait and see who the Necurs team is and what they have in store for us, and if this was one of those big upgrade moments.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS