Skip to main content

Necurs botnet distributing Dridex

Threat Intelligence monitoring has identified a Necurs distribution campaign. Necurs is a large botnet that is known to distribute various types of malware, including; banking Trojans and ransomware.

Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Threat Intelligence monitoring has identified a Necurs distribution campaign. Necurs is a large botnet that is known to distribute various types of malware, including; banking Trojans and ransomware.


Threat details

The email contains an attached PDF file that contains a Word document which leads to Dridex. There appears to be several variants, and currently have a low detection rate, therefore vigilance is advised if any attachments aren’t blocked by email filtering.


Remediation steps

Type Step
Keep malware definitions up-to-date.
Never open email attachments or click on links from untrusted sources.
Make sure that cyber awareness training is kept up-to-date.

Last edited: 9 October 2020 11:49 am