Microsoft, BitSight, and partners in 35 countries carried out coordinated legal and technical action to disrupt Necurs, a long-running criminal botnet used to send massive spam campaigns and deliver malware including ransomware, banking trojans, cryptominers, and credential stealers. Microsoft said Necurs had infected more than 9 million computers, while BitSight estimated roughly 2 million systems remained dormant after the botnet’s activity slowed in 2019. A U.S. court order allowed the seizure of U.S.-based infrastructure, and defenders also reverse-engineered Necurs’ domain generation algorithm to predict more than 6 million future domains for blocking by registries, aiming to cut off both current command-and-control channels and future recovery attempts.
The takedown targeted a botnet that had evolved for years into a flexible malware delivery platform with rootkit capabilities and changing monetization tactics. Prior reporting tied Necurs to Locky and Dridex distribution, pump-and-dump stock spam, .URL attachment chains that fetched second-stage loaders over SMB, and selective deployment of tools such as XMRig and FlawedAmmyy RAT after profiling infected systems for wallets, enterprise environments, and sector-specific targets. Researchers also documented Necurs’ multi-stage domain generation and fallback mechanisms, underscoring why sinkholing and domain blocking were central to the disruption effort and why global remediation by ISPs, CERTs, governments, and law enforcement remained necessary.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
On March 10, 2020, Microsoft, BitSight, and partners in 35 countries announced coordinated legal and technical actions to disrupt the Necurs botnet. The operation targeted existing infrastructure and used analysis of Necurs' domain generation algorithm to predict and report more than six million future domains for blocking, while remediation partners worked to clean infected systems.
On Thursday, March 5, the U.S. District Court for the Eastern District of New York issued an order enabling Microsoft to take control of U.S.-based infrastructure used by Necurs. Microsoft said the order supported a broader effort to disrupt the botnet and block future domains.
For the first seven days of March 2020, BitSight sinkhole telemetry showed India with the highest observed infection count, followed by countries including Indonesia, Turkey, Vietnam, Mexico, Thailand, Iran, and the Philippines. The data illustrated Necurs' continued global footprint despite stalled activity.
BitSight reported that Necurs botnet activity had stalled since March 2019, although about 2 million infected systems were estimated to remain dormant awaiting reactivation. BitSight also observed only a slight decrease in infections over time after the stall.
On June 11, 2018, Trend Micro observed Necurs pushing a .NET spamming module that could send email through victims' accounts, steal browser credentials, access contact lists, and hide evidence of sent spam. Parts of the module overlapped with QuasarRAT.
In late May 2018, Necurs modules searched Outlook directories for filenames containing email strings and exfiltrated those identifiers to a remote PHP endpoint. A few days later, researchers saw new modules using hardcoded email lists to decide where to deploy FlawedAmmyy.
In April 2018, Trend Micro observed Necurs pushing the FlawedAmmyy remote access trojan to selected bots that matched targeting criteria such as cryptocurrency, banking, enterprise, POS, or email-related indicators. The malware exfiltrated host details after installation.
Trend Micro observed Necurs deploying the XMRig cryptocurrency miner to infected systems in March 2018. The campaign mined Monero using a wallet that researchers said was earning about USD 1,200 in 24 hours at the time of observation.
On June 21, 2017, Talos reported a Necurs campaign sending fake invoice emails with executables nested in double ZIP archives to distribute Locky ransomware. The analyzed build appeared hastily deployed and only successfully affected Windows XP systems because its unpacker crashed on newer Windows versions.
On March 20, 2017, researchers saw a major resurgence of Necurs spam promoting InCapta Inc. ticker $INCT rather than delivering malware. Talos observed tens of thousands of emails, a second higher-volume wave, and coinciding increases in trading volume and stock price.
On December 20, 2016, researchers observed a Necurs-linked pump-and-dump spam campaign promoting stock ticker $SWRM. Talos later linked it to a March 2017 campaign through shared headers and other attributes.
Talos reported that Necurs went offline in late December 2016, contributing to a major drop in high-volume Locky malspam. The downtime preceded its later return with stock-manipulation spam.
Microsoft and BitSight said Necurs was first observed in 2012. Trend Micro also described Necurs as existing since 2012.
Trend Micro reported that newer Necurs campaigns used disguised .URL internet shortcut files to fetch remote scripts over SMB, adding QUANTLOADER as another stage before the final payload. The change was described as an evolution intended to evade spam filtering and endpoint detection.
In May, Necurs had shifted from Locky to Jaff, but after Kaspersky found a vulnerability enabling a Jaff decryptor, operators reverted to distributing Locky. Talos described the return as an apparent response to Jaff being undermined.
An analysis documented Necurs using connectivity checks, hard-coded pseudo-DGA domains, and a fallback DGA that could generate up to 2,048 domains across 43 TLDs. The report assessed the hard-coded domains as likely main command-and-control targets and the first DGA as an anti-analysis mechanism.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
shadowserver.org
Open sourceblogs.microsoft.com
Open sourcebitsight.com
Open sourceblog.trendmicro.com
Open sourceblog.trendmicro.com
Open sourceblog.talosintelligence.com
Open sourceblog.talosintelligence.com
Open sourcebin.re
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.