Necurs, also known as CraP2P, was a long-running Windows hybrid peer-to-peer botnet and malware distribution platform first observed in 2012. It combined hard-coded command-and-control infrastructure, multiple domain-generation algorithms, and peer-to-peer communications to maintain resilient control over infected hosts. A variant used Namecoin to store command-and-control domain information as early as 2013. At its peak, Necurs infected millions of systems globally and was one of the most prolific sources of malicious bulk email; coordinated legal and technical action disrupted much of its infrastructure in March 2020.
Necurs primarily enabled criminal operators by distributing malspam and secondary malware, including GameOver Zeus, Dridex, Locky, Trickbot, Scarab, GlobeImposter, XMRig, and FlawedAmmyy. Campaigns commonly used social-engineering emails with compressed attachments containing scripts or Internet Shortcut files. Some chains used nested archives, disguised shortcut files, and remote SMB-hosted download stages to evade email and endpoint defenses. Necurs was also used for stock-promotion fraud, fake-pharmaceutical spam, and dating scams.
The modular botnet could distribute spam and proxy modules, deploy cryptocurrency miners, profile compromised hosts, steal browser credentials and email-related data, and selectively deploy remote-access malware. Its targeting logic checked for cryptocurrency-wallet artifacts, banking-related environments, point-of-sale processes, large enterprise networks, and selected email accounts. A later spam module could abuse authenticated Outlook, Gmail, and Yahoo sessions to send messages through victims’ accounts, access contact data, and remove evidence of sent spam. Necurs operators are widely assessed as cybercriminals likely based in Russia; the botnet was also used as a distribution service by other malware operators, so payload delivery alone does not establish common attribution among all customers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
En 2011, apparaît le botnet Necurs (alias CraP2P)... TA505 aurait massivement distribué des codes malveillants via le botnet Necurs.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
They have all been used to deliver much of the spam, phishing lures and malware that was received globally.
The malware infects a victim’s system by being dropped by other malware, through either spammed email attachments or malicious advertisements.
Once on a system, Necurs utilizes its kernel mode rootkit capabilities to disable a large number of security applications, including Windows Firewall, both to protect itself and other malware on the infected system.
Necurs malware uses this to its advantage by changing the folder icon to trick the victim into thinking that it’s a different file type... The .URL file disguised as a .ZIP file of a voicemail message
the .NET module can delete the last email sent from the victim’s email account and catch all alerts.
The modules execute commands such as “net view” and “net user” to check for the following strings
The Necurs modules check if the machines have files that contain any of the following strings that exist under “%APPDATA%” such as: WALLET.DAT BITCOIN-QT ELECTRUM
The malware then contacts three NTP pools to get the accurate date and time.
The modules execute “net user” and “net domain” to see if a machine is connected to a network with more than 100 users.
Necurs starts by checking internet connectivity by resolving facebook.com or microsoft.com... The purpose of the domains is to detect simulated internet in lab environments.
The module will search for the files with email strings in the filenames and send those strings back.
The Necurs botnet makes use of hardcoded domains and multiple layers of DGAs to attempt to guarantee reliable command and control (C2) capabilities.
Threat actors use peer-to-peer (P2P) botnets like these to build a platform that can later be used to carry out malicious operations... The need for increased takedown resistance eventually drove botnet operators to adapt and explore peer-to-peer approaches.
“The technique, named Blockchain Dead Drops (BDD), stores payloads in on-chain transactions and smart contracts where infected devices can retrieve them on demand.” The article explicitly maps it to “T1102.001 (Web Service: Dead Drop Resolver).”
« Blockchain Dead Drops (BDD) ... stocker des instructions de malware ou des configurations C2 sur des blockchains publiques » ; « Smart contracts sur Polygon utilisés comme résolveurs C2 ».
The Necurs botnet has historically been used to deliver a torrent of other high profile cyber threats to the world, including the GameOver Zeus and Dridex banking trojans, Locky ransomware and, more recently, the banking trojan turned all purpose cybercrime-as-a-service, Trickbot.
In April, we observed that it pushed the remote access trojan FlawedAmmyy onto its bots.
We would usually provide in-depth details here about the technical functionality of the Necurs malware, reverse engineering information, the use of multiple layers of Domain Generation Algorithms (DGAs) – including .bit for blockchain based name to IP address resolution...
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Necurs botnet variant used Namecoin to store command-and-control domain information, an early example of blockchain dead-drop infrastructure.
A Necurs botnet variant stored command-and-control domains on the Namecoin blockchain.
A Necurs botnet variant used Namecoin to store command-and-control domain information, representing an early blockchain dead-drop technique.
Named as one possible botnet distribution mechanism for ransomware, but not a focus of the article.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.