Created by Ajay Kumar
Last edited September 26, 2023


The Necurs botnet is a distributor of many pieces of malware, most notably Locky.

Reports[edit | edit source]

Around June 1, 2016, the botnet went offline, perhaps due to a glitch in the command and control server running Necurs. However, three weeks later, Jon French from AppRiver discovered a spike in spam emails, signifying either a temporary spike in the botnet's activity or return to its normal pre-June 1 state.[1][2]

In a 2020 report, it was noted to have particularly targeted India, Southeast Asia, Turkey and Mexico.[3]

Distributed malware[4][edit | edit source]

See also[edit | edit source]

References[edit | edit source]

  1. French, Jon (27 June 2016). "Necurs BotNet Back With A Vengeance Warns AppRiver". Retrieved 27 June 2016.
  2. "Pump and dump spam: Incapta Inc (INCT)". Retrieved 22 Mar 2017.
  3. "Microsoft Hijacks Necurs Botnet that Infected 9 Million PCs Worldwide". The Hacker News.
  4. "Hackers behind Locky and Dridex start spreading new ransomware". Retrieved 27 June 2016.


Template:Malware-stub