Necurs is a long-running modular Windows botnet malware family first observed in 2012 and widely recognized as one of the largest criminal spam and malware distribution platforms of its era. It operated as a hybrid peer-to-peer botnet with resilient command-and-control mechanisms that included hardcoded infrastructure and domain generation algorithms, enabling large-scale spam operations and sustained malware delivery. Necurs infected millions of systems globally and remained active for years before a major multinational disruption effort in 2020.
Necurs is primarily known as a malware delivery and spam service used by cybercriminal operators and affiliates. It has been used to distribute financially motivated malware and ransomware families including Dridex, Locky, Trickbot, GameOver Zeus, Scarab, and GlobeImposter, and it was heavily associated with large malspam campaigns from roughly 2016 through 2019. Campaigns attributed to or delivered through Necurs commonly relied on email lures with compressed attachments, nested archives, script downloaders, and later internet shortcut files designed to evade filtering and endpoint detection. Malspam themes included invoices, payment notices, order confirmations, scanner-themed messages, and other business-relevant pretexts.
The malware is modular and supports multiple operational roles across infected hosts. Reported capabilities include spam distribution, downloading and installing additional payloads, information theft, proxy functionality, targeted deployment of remote-access malware, and disabling security controls. Necurs has also been observed delivering cryptocurrency miners such as XMRig and selectively deploying FlawedAmmyy RAT to systems matching targeting criteria. Targeting logic examined infected environments for signs of cryptocurrency wallets, banking relevance, large enterprise networks, point-of-sale processes, and email identifiers associated with sectors such as government, finance, tourism, food, and real estate. Additional modules were observed harvesting Outlook-related email identifiers and testing spam-sending through victims’ legitimate email sessions while suppressing visible evidence.
Necurs also incorporated defensive and persistence-oriented tradecraft. It has been described as using kernel-mode rootkit functionality and disabling security applications, including Windows Firewall. Variants were observed using layered infection chains and delivery intermediaries such as QUANTLOADER to complicate detection and analysis. Some campaigns used SMB-hosted second stages triggered by disguised shortcut files rather than directly embedding the downloader in the attachment archive.
Operationally, Necurs functioned as a botnet-for-hire or distribution service for multiple criminal customers rather than a single-payload operation. It was heavily used by actors such as TA505 for large-scale phishing and malware delivery, though not every payload delivered through Necurs can be attributed to the same downstream actor. Its scale, modularity, and resilient infrastructure made it a central component of the email-borne cybercrime ecosystem until coordinated legal and technical disruption significantly degraded the botnet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
En 2011, apparaît le botnet Necurs (alias CraP2P)... TA505 aurait massivement distribué des codes malveillants via le botnet Necurs.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
They have all been used to deliver much of the spam, phishing lures and malware that was received globally.
The malware infects a victim’s system by being dropped by other malware, through either spammed email attachments or malicious advertisements.
Once on a system, Necurs utilizes its kernel mode rootkit capabilities to disable a large number of security applications, including Windows Firewall, both to protect itself and other malware on the infected system.
Necurs malware uses this to its advantage by changing the folder icon to trick the victim into thinking that it’s a different file type... The .URL file disguised as a .ZIP file of a voicemail message
the .NET module can delete the last email sent from the victim’s email account and catch all alerts.
The modules execute commands such as “net view” and “net user” to check for the following strings
The Necurs modules check if the machines have files that contain any of the following strings that exist under “%APPDATA%” such as: WALLET.DAT BITCOIN-QT ELECTRUM
The malware then contacts three NTP pools to get the accurate date and time.
The modules execute “net user” and “net domain” to see if a machine is connected to a network with more than 100 users.
Necurs starts by checking internet connectivity by resolving facebook.com or microsoft.com... The purpose of the domains is to detect simulated internet in lab environments.
The module will search for the files with email strings in the filenames and send those strings back.
The Necurs botnet makes use of hardcoded domains and multiple layers of DGAs to attempt to guarantee reliable command and control (C2) capabilities.
Threat actors use peer-to-peer (P2P) botnets like these to build a platform that can later be used to carry out malicious operations... The need for increased takedown resistance eventually drove botnet operators to adapt and explore peer-to-peer approaches.
The Necurs botnet has historically been used to deliver a torrent of other high profile cyber threats to the world, including the GameOver Zeus and Dridex banking trojans, Locky ransomware and, more recently, the banking trojan turned all purpose cybercrime-as-a-service, Trickbot.
In April, we observed that it pushed the remote access trojan FlawedAmmyy onto its bots.
There are two types of seeded DGAs... Dynamically seeded DGAs: Dynamic DGAs use time-based seeds, making it difficult to predict domain names. Security researchers can anticipate domains generated by date-based seeds, enabling proactive blocking. However, unpredictable seeds like Google Trends or FX rates remain a challenge, even with access to the source code.
We would usually provide in-depth details here about the technical functionality of the Necurs malware, reverse engineering information, the use of multiple layers of Domain Generation Algorithms (DGAs) – including .bit for blockchain based name to IP address resolution...
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one possible botnet distribution mechanism for ransomware, but not a focus of the article.
Botnet used to distribute malspam carrying archive attachments that lead to VBS downloaders and ultimately the Scarab ransomware payload.
A botnet referenced as a prior takedown target; mentioned in the context of earlier disruption operations preceding the cracked Cobalt Strike-focused effort.
Botnet malware observed with modified dynamic DGA seed behavior, producing domains outside expected time windows to hinder defensive prediction and blocking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.