Microsoft said it led the effort to take down Necurs, a malware botnet that infected more than 9 million computers globally, working with partners in 35 countries including cybersecurity ratings company BitSight.
Necurs, believe to be operated by cybercriminals in Russia, is used to send spam emails containing financially targeted malware and ransomware like the GameOver Zeus banking trojan, cryptomining, and distributed denial of service (DDoS) capabilities. Microsoft says that during a 58-day period in its investigation, it observed that one Necurs-infected computer sent a total of 3.8 million spam emails to more than 40.6 million potential victims.
Once the attacker uses the spam email to infect a network of computers with malware it can then control those computers remotely and use them to commit crimes. Necurs has been used to attack other computers on the internet, steal credentials for online accounts, and steal personal information and confidential data.
Between 2016 and 2019, it was the most prominent spam and malware-delivery method and was responsible for 90% of the malware spread by email worldwide, according to BitSight.
“Once on a system, Necurs utilizes its kernel mode rootkit capabilities to disable a large number of security applications, including Windows Firewall, both to protect itself and other malware on the infected system,” according to a BitSight blog. “Necurs is modular in that it allows the operators to change how they operate it over time.”
Microsoft’s Digital Crimes Unit, BitSight, and other security researchers first observed the Necurs botnet in 2012. Late last week, the U.S. District Court for the Eastern District of New York issued an order allowing Microsoft to take control of U.S.-based infrastructure Necurs uses to distribute malware and infect victim computers. The company analyzed a technique that Necurs used to generate new domains through an algorithm and then was able to predict more than 6 million unique domains that would be created in the next 25 months.
“Microsoft reported these domains to their respective registries in countries around the world so the websites can be blocked and thus prevented from becoming part of the Necurs infrastructure,” Microsoft’s Tom Burt, corporate VP of customer security and trust, wrote in a blog post. “By taking control of existing websites and inhibiting the ability to register new ones, we have significantly disrupted the botnet.”
The takedown also included internet service providers, domain registries, government agencies, and law enforcement in Mexico, Colombia, Taiwan, India, Japan, France, Spain, Poland, and Romania, among others.
Heavy Patch TuesdayThe Necurs takedown announcement follows a particularly heavy Microsoft Patch Tuesday, which attempts to fix at least 115 security flaws. Microsoft rated 26 of these “critical.”
The critical flaws includes a remote code execution vulnerability (CVE-2020-0852) in Microsoft Word that, if left unpatched, could allow an attacker to use a specially crafted file to perform actions on behalf of the logged-in user with the same permissions as the current user, according to a blog post by Animesh Jain, a member of Qualys’ expert vulnerability management research team.
Another remote code execution vulnerability (CVE-2020-0872) in Application Inspector is labeled “important,” a step below “critical,” by Microsoft but should be prioritized, Jain said. “This vulnerability can allow an attacker to execute their code on a target system if they can convince a user to run Application Inspector on code that includes a specially crafted third-party component,” Jain wrote.
Comments