• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • Trend Micro: Hackers Add New Features to Necurs botnet malware
  • Malware

Trend Micro: Hackers Add New Features to Necurs botnet malware

Ddos April 28, 2018 4 minutes read

Necurs is known as the Malware Trojan Transmission Infrastructure and there have been several cases of spreading of malicious family Trojans that have been proved or suspected to be related to the botnets built by Necurs Trojans, including the notorious rogue viruses Locky, Jaff, mainly bank vouchers. Target Trojan Dridex et al. Necurs is more than just a spam tool. It also has rootkit capabilities and the ability to fight against killing software. Once infected with a user’s machine, it is difficult to get rid of. In addition, Necurs has implemented a modular design that can load different malicious modules according to different tasks, allowing the victim’s computer to be manipulated arbitrarily.

Necurs is a botnet malware that emerged around 2012 and has never stopped optimizing updates since its appearance. Millions of infected computers are under its control and about one million devices are activated each day. Necurs has been engaged in spamming cybercrime activities for many years.

In 2017, the Necurs botnet added C&C server communication capabilities that can be used to launch DDoS attacks. The module spreads malicious traffic through infected hosts, mainly through the HTTP, SOCKSv4, and SOCKSv5 protocols.

McAfee released a report in March 2018 saying that in the fourth quarter of 2017, spam sent by botnet Necurs and Gamut accounted for 97% of all spam. During this time, Necurs used the adult website as a lure for its delivery and transfer program, providing POC for ransomware. The spam activity rate was slightly lower than the previous two months, but the botnet still accounted for 37% of all spam, Necurs accounted for 60%, and most of the e-mail domain names were linked to job-themed phishing and Related to money fraud.

In January 2018, a blog posted by e-mail and cybersecurity company AppRiver stated that AppRiver’s SecureTide filter blocks up to 47 million junk e-mails sent from Necurs botnets to App River customers every day. Distribution of ransomware Locky and GlobeImposter.

The spam e-mails usually issued by Necurs botnets are called pumping and dumping. They rely on sending a lot of spam to promote the user’s interest in specific low-priced stocks. The spammers purchase the stocks at a low price in advance. When the spam activity raises the price, the stock is sold at a higher price.

Trend Micro recently discovered that a new variant of Necurs, the world’s largest spam botnet, appeared and evaded detection via a network shortcut (.url) file.

Necurs previously used an archive file containing a .ZIP file to hide the script download program in order to avoid attachments being detected. The download program was then packaged in another .ZIP file to hide.

Unlike previous Necurs variants, the new variant uses a network shortcut file to send malicious spam to download program scripts.

The script then executes remotely through the Server Message Block (SMB) protocol to evade spam filter detection.

This script will generate a secondary downloader, QuantLoader (this is a common malware family), whose purpose is to obtain boot persistence, and finally download the final, more powerful Payload from this downloader. Botnet operators rarely use this simple spam technique and have always relied on complex infection chains.

Trend Micro researchers pointed out that using QuantLoader may achieve a multiplier effect. First, this download program adds another download phase before downloading the final Payload, which can confuse and evade behavior detection. The QuantLoader is persistent, releasing a copy of itself and creating an autorun registry for execution at startup.

Trend Micro reported in the report that the attacker behind this activity is also using the ability to modify the Internet shortcuts to click on the icon, in order to trick victims into thinking that they are receiving normal folders. In a spam sample, an attacker disguised a URL file as a ZIP file for voice mail.

If the user receives an e-mail attachment that contains the shortcut file shown below, this file is 100% malicious and should never be opened.

 

In January 2018, the Necurs botnet spawned millions of spam emails. For the first time, large-scale spam campaigns promoted a little-known cryptocurrency Swisscoin cryptocurrency, instead of pushing low-priced stocks, as usual, resulting in Swisscoin lost 40% of the initial transaction price.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Mirai Okiru: The first new Linux ELF malware designed to infect ARC CPUs
  2. FAUST Ransomware Strikes: The Hidden Dangers Inside Office Documents
  3. Malicious Models on Hugging Face: A New Threat to AI Development
  4. TROX Stealer: Urgency-Themed MaaS Malware Targets Consumer Data
  5. The “Compatibility” Trap: New Mac Malware Tricks Users into Bypassing TCC
Tags: Necurs botnet malware

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.