Necurs botnet is back online after mysterious 3-week hiatus
Necurs – one of the world's largest botnets – is back online after mysteriously going dark for three weeks. The botnet's activities had come to a grinding halt on 31 May when its central C&C (command and control) servers went offline after which security researchers immediately began noticing a drop in spam activities driven by the Locky ransomware.
MalwareTech told IBTimes UK that it first noted some activity early on 12 June, "but it seemed unorganised and looks like a sinkhole attempt as the servers were not responding properly". However, it was a week later, on 19 June that it became clear that Necurs had been activated. "The servers began issuing proper replies though they still remained silent command wise. Around 6.32pm GMT yesterday the botnet issued its first command since 31 May, which began a new spam campaign sending out Locky infected emails, confirming the original botmasters were back in control."