Microsoft, along with a team of specialists from 35 countries, has successfully disrupted and disabled an international zombie bot network.
Necurs, the organisation that has infected over nine million computers, is the largest network of botnets in the world and has victims in every country. During a 58-day period in Microsoft’s investigation into Necurs, infected computers sent a total of 3.8 million spam emails to over 40.6 million potential victims.
Corporate VP, customer security & trust at Microsoft, Tom Burt, commented in a blog post: “Today, Microsoft and partners across 35 countries took coordinated legal and technical steps to disrupt one of the world’s most prolific botnets, called Necurs, which has infected more than nine million computers globally.
“This disruption is the result of eight years of tracking and planning and will help ensure the criminals behind this network are no longer able to use key elements of its infrastructure to execute cyberattacks.”
It is believed that the Necurs hackers are based in Russia and have used a carried out a variety of crimes including pump-and-dump stock scams, fake pharmaceutical spam emails and “Russian dating” scams.
Burt continued: “The criminals behind Necurs sell or rent access to the infected computer devices to other cybercriminals as part of a botnet-for-hire service.
“Necurs is also known for distributing financially targeted malware and ransomware, cryptomining, and even has a DDoS (distributed denial of service) capability that has not yet been activated but could be at any moment.”
Microsoft analysed a technique used by Necurs themselves to generate new domains through an algorithm. It was then possible to accurately predict over six million unique domains that would be created in the next 25 months. The company then reported these to their respective registries in countries so the websites can be blocked, thus preventing them from becoming part of the Necurs infrastructure.
Recommended
- AI Market to See Five-Fold Increase Globally by 2025
- 150,000 Cybersecurity Professionals From 175 Countries Join (ISC)²
- Patient Care Platform Targets National Roll-out After Successful Trials
“By taking control of existing websites and inhibiting the ability to register new ones, we have significantly disrupted the botnet,” Burt said.
The Necurs network has previously been flagged by Microsoft when malware called the ‘GameOver Zeus banking trojan’ was used in 2012 to steal passwords. Microsoft worked with the FBI to find and remove it from their systems. The bot was said to have infected between 500,000 and 1 million computers worldwide, and the FBI estimated that Gameover Zeus was responsible for more than $100 million (£77 million) in losses.
In this latest operation, Microsoft said it was “working with ISPs, domain registries, government CERTs and law enforcement in Mexico, Colombia, Taiwan, India, Japan, France, Spain, Poland and Romania, among others”.
Burt concluded: “Each of us has a critical role to play in protecting customers and keeping the internet safe.”





