DDoS Capability Added to Necurs
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Necurs is a modular piece of malware which allows different modules to be added in order to increase its capabilities. In this scenario, Necurs has added a DDoS module to its malware. The module was identified in September 2016 with a timestamp indicating that it was added to the malware in August 2016. There are no indications that the botnet has been used for a DDoS attack since it was added last year.
The Necurs botnet currently has over 1 million compromised Windows based PC’s and is continuing to grow. With the malware now having DDoS capabilities and having this number of bots, it would be able to produce a very strong attack.
Remediation steps
Last edited: 17 February 2020 11:29 am