Categories: NewsSecurity

Necurs Botnet Developers Add DDoS Capabilities To Their Modular Malware

The last thing this world needs is botnets getting even more capable of causing havoc. Unfortunately, that is exactly what is happening with the Necurs botnet right now. In a recently update by the developers, this botnet malware has added a new trick to successfully execute DDoS attacks. It seems to be only a matter of time until the next global denial-of-service attack is initiated by a botnet operator.

A Big Update Makes Necurs Even More Dangerous

Up until this point, security researchers were concerned about Necurs malware delivering Locky ransomware to its victims. While that is disconcerting in its own right, the Necurs botnet developers are upping the ante once again. Their new update allows this tool to execute distributed denial-of-service attacks with relative ease once it infected a target computer. Once again, cyber criminals are stepping up their game

It is rather intriguing to note the Necurs source code was modified in September of 2016 to allow for DDoS attack capabilities. Additionally, a new proxy command-and-control communication feature was added around the same time. However, the botnet has not launched a successful DDoS attack so far, which leaves security researchers baffled. Then again, not having to deal with DDoS attacks is never a bad thing.

There are plenty of other things to worry about when it comes to Necurs, though. It is believed the malware has successfully infiltrated over one million Windows computers around the world. For now, this malware does not target Mac OS X and Linux users, although new variants may be introduced at a later date. Considering how Necurs is a modular malware, there is no limit as to what it may be capable of one year or one week from now.

Related Post

To put this source code change into perspective, Necurs will make HTTP or UDP requests to any target decided upon by its creators. These requests will continue in an endless loop, which is very similar to how DDoS attacks work these days. With over 1 million infected computers at the developers’ disposal, a lot of damage can be done if someone decides to flip the proverbial switch.

It is important to keep in mind this recent change does not mean Necurs will no longer be used to distribute the Locky ransomware. After all, the malware has been most successful while doing so, and it is doubtful the developers will stop using this method anytime soon. The addition of executing DDoS attacks will only make this toolkit more popular among cybercrime gangs than before, as it is slowly evolving into a complete package to cause major havoc.

Moreover, this updated Necurs malware is capable of executing two different types of denial-of-service attacks. First of all, there is HTTPFlood, which will mainly target sites not using HTTPS. UDPFlood, on the other hand, will be used against all other targets the malware comes across. Evidently, it is only a matter of time until a major attack comes forth from this botnet, albeit it is anybody’s guess who will be targeted in the process.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Michael Saylor Breaks Down Bitcoin’s Four Ideologies And Warns Against Picking Just One

Michael Saylor just handed the Bitcoin community something to argue about for weeks. The Strategy…

12 hours ago

Solana Largest Treasury Company Dumps 455,000 SOL as Price Crashes to Lowest Level in 2.5 Years

Solana is having one of its worst weeks in recent memory, and the news keeps…

13 hours ago

Hyperliquid Strategies Buys $95M Worth of HYPE in Seven Days While Barely Touching Its Cash

Hyperliquid Strategies, the decentralized autonomous trust behind the $PURR ticker, just pulled off something that…

2 days ago

Arthur Hayes Dumps $18 Million in HYPE and NEAR

Arthur Hayes does not exit quietly. The BitMEX co-founder has liquidated his entire positions in…

2 days ago

Jupiter Launches Forecast, Solana’s First Fully Native Prediction Market With Competing Market Makers

Jupiter is not done building. The team behind one of Solana's most used trading platforms…

2 days ago

Ethena Expands Partnership With Anchorage Digital to Strengthen Institutional Lending

Ethena is not slowing down. The protocol just announced an expanded partnership with Anchorage Digital,…

2 days ago