Necurs botnet reappears with Locky ransomware

Malware-spreading botnet reactivated after weeks of silence


Security researchers have confirmed that one of the world's largest botnets has reactivated and resumed distributing Locky and Dridex malware payloads.

The Necurs botnet was shut down in early June, but appears to have returned.

"On the evidence of reused IP addresses, this campaign appears to be originating from the Necurs botnet," security company Proofpoint wrote in a blog post.

"As of the writing of this blog on 22 June, a second, much larger Locky campaign was underway, signaling a clear return of both Locky and the Necurs botnet."

Advertisement - Article continues below
Advertisement - Article continues below

The Necurs botnet is believed to be one of the biggest currently in operation, but on 1 June, Proofpoint noticed that activity around it sharply dropped off.

At the same time, campaigns of ransomware emails - which Proofpoint described as "among the largest we have ever observed" - also dropped substantially in volume.

This confirmed that the Necurs botnet was being used by cybercriminals as a ransomware delivery channel. As well as the Locky strain of ransomware, it was also used to distribute the Dridex banking trojan, which steals users' financial credentials.

After almost a month of inactivity, emails loaded with Locky and Dridex have begun to circulate again, which Proofpoint said suggests that "the Necurs spam cannon is functional again".

Even more worryingly, the Locky instances feature upgrades designed to thwart detection and analysis, introduced by the authors just before Necurs' outage. These include counting CPU cycles to identify virtual machines, Javascript obfuscation and obscuring loader details.

The volume of emails is just 10 per cent of the campaign's previous peak, but Proofpoint warned "unfortunately, we expect both Dridex and Locky email campaigns to begin again in earnest".

Advertisement - Article continues below

The reappearance comes in the wake of news that crypto-ransomware attacks - including attacks using malware like Locky - have risen more than 550 per cent over the last year.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now


internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
cyber security

If not passwords then what?

8 Jan 2020
Policy & legislation

GDPR and Brexit: How will one affect the other?

9 Jan 2020
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020