Attacks/Breaches
2/28/2017
05:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Massive Necurs Spam Botnet Now Equipped to Launch DDoS Attacks

With more than one million active bots at any time, a Necurs-enabled DDoS attack could dwarf such an attack by the Mirai botnet.

In an ominous development, the world’s largest spam botnet has acquired capabilities that could allow it to be used in massive distributed denial-of-service attacks.

Security researchers at BitSight’s Anubis Labs recently observed the Necurs botnet loading a component in infected systems that allow the systems to perform DDoS attacks.

The addition of the new component appears to have started at least six months ago, which is when BitSight researchers first observed some unusual communications on a Necurs-infected system.

In addition to communicating via port 80, the Necurs-infected system was also using a different port  as well as what appeared to be a different protocol, to communicate with a set of command and control addresses.

A subsequent analysis showed the communications from the infected system to be requests to download two separate modules. One of them was for the usual spam distribution purposes. And the other was for a proxy module that would cause the bot to make HTTP or UDP requests to a target system "in an endless loop," BitSight said in a recent alert.

The bot is modular in design; the proxy and DDOS features are part of a module first was deployed in September, says Tiago Pereira, threat intelligence researcher at Bitsight's Anubis Labs. "The SOCKS/DDOS module is being loaded in all the bots in the botnet," he says. At the same time, the spam modules are also still being loaded on all infected system, he says.

Pereira says BitSight's sinkholes measured an average of over 1 million active Necurs infected system every single day. "Simply taking into account its size—more than double the size of Mirai—we would expect it to produce a very powerful DDoS attack," he says.

Security researchers estimate the overall size of the Necurs botnet to be upwards of 5 million infected systems, though only about 1 million are active at any give time. In addition to being used for spam distribution, the botnet has also been used to deliver the notorious Locky ransomware and the Dridex banking Trojan.

The botnet went offline somewhat inexplicably for a few weeks last year, resulting in an almost immediate drop-off in Locky and Dridex distributions. But it came back online equally inexplicably and with renewed vigor in June, and since then had been used to distribute spam and malware.

With the addition of the new DDoS module, Necurs appears set to become even more versatile than it is already.

Ben Herzberg, security group research manager at Imperva, says it's interesting that Necurs has now added a feature for DDoS attacks. But threat actors are likely to increasingly favor using IoT botnets such as Mirai because they are easier to infect and use than desktop botnets like Necurs, he said.

"Therefore, it seems likely that this is either a test module, or something to be used in a 'doomsday scenario' – for example when the botnet operators need it for a very good reason - not just as a normal DDoS-for-hire campaign," he said in a statement.

Word of the Necurs botnet update comes amid reports of changes to Neutrino, another well-known malware sample that has been used to assemble a large botnet. The authors of the Neutrino bot have developed a new protective loader that makes it harder for malware tools to detect the bot, Malwarebytes Labs said in an alert this week.

The new loader is designed to check whether it is being deployed in a controlled environment like a sandbox or a virtual machine and to delete itself automatically if that is indeed the case, Malwarebytes researchers Hasherezade and Jerome Segura said.

The tweak is not major. But the new protection layer is "very scrupulous in its task of fingerprinting the environment and not allowing the bot to be discovered," they said.

Related stories:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Jet Hedon
100%
0%
Jet Hedon,
User Rank: Apprentice
3/1/2017 | 7:09:21 AM
Great info
Great info you shared here. Studying DDOS right now, this article helped me out to learn more.
3 Ways to Retain Security Operations Staff
Oliver Rochford, Vice President of Security Evangelism at DFLabs,  11/20/2017
A Call for Greater Regulation of Digital Currencies
Kelly Sheridan, Associate Editor, Dark Reading,  11/21/2017
New OWASP Top 10 List Includes Three New Web Vulns
Jai Vijayan, Freelance writer,  11/21/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Managing Cyber-Risk
An online breach could have a huge impact on your organization. Here are some strategies for measuring and managing that risk.
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.