Huge malware network goes into hibernation



One of the biggest networks of spam-sending computers in the world has gone quiet, puzzling experts, internet security firms have said.


For years the Necurs botnet has distributed junk mail and malware for many different groups of cyber-thieves.

But the amount of malicious traffic emerging from Necurs has now dwindled to almost nothing.

It is not clear what has caused the slowdown and whether traffic will return to previously high levels.

One of the first signs of the disruption was seen earlier this month when email messages spreading the Dridex banking trojan and Locky ransomware caught by security firms dried up.

Typically, millions of messages bearing these malicious programmes are sent out every week, Proofpoint said in a blogpost, according to BBC.

However, the flood of messages "essentially stopped" last week, it said. Investigations revealed that these messages typically travelled via the Necurs botnet which was found to have gone largely offline.

The Necurs botnet is believed to be made up of about six million compromised Windows machines, many of which were enrolled when their owners inadvertently fell victim to a form of malware known as a rootkit.

Analysis of some of the machines known to be part of Necurs shows that its core administration systems have disappeared, said Proofpoint.

Security researchers who monitor botnets and the groups that operate them said the cause of the shutdown remained a mystery.

"We cannot confirm how the botnet was brought down yet," Joonho Sa, a researcher for FireEye, told tech news site Motherboard.

Source: The Financial Express

Post a Comment

0 Comments