Connect with us

Hi, what are you looking for?

Tech & Science

Ransomware-spreading botnet takes desktop screenshots

The ransomware was discovered recently by researchers at Symantec, who say the group behind Necurs has added some additional functions to its toolkit, primarily a downloader, to gain some additional insights into its victims, hence the screenshots being collected. The screenshots are then sent back to a remote server.

However, the hackers have upgraded their malware, as it now includes an error-reporting feature that sends information back to the cyber-attackers on any issues their downloader may encounter. Symantec suggests the hackers are using the error-reporting function to check on the performance of their malware, much the same as legitimate software companies collect crash reports.

The Necurs botnet has only been in existence for five years, but its reach has been phenomenal, allowing it to reach and take over up to 6 million zombie endpoints. This allows them to download some of the worst banking Trojans and ransomware threats in batches of millions of emails at a time.

Basically, Necurs botnet is indirectly responsible for a major portion of cybercrimes, and worldwide, damages incurred by this group are estimated to surpass $ 6.0 trillion by 2021, according to Security Intelligence.

Fake invoices – Do not open them
Symantec writes: “The new emails use a tried-and-tested invoice-based social engineering format, and generally, contain the following details:
Subject: Status of invoice [FAKE INVOICE NUMBER]
Attachment: [FAKE INVOICE NUMBER].html

Typical invoice email sent by Necurs botnet.

Typical invoice email sent by Necurs botnet.
Symantec


The body of the email contains a message urging the reader to open the attachment to check the invoice.
Standard precautions apply here; when strangers offer you unsolicited invoices or deliveries via email, the safest course of action is to simply trash the email.
If the attached .html file is opened, it will download a JavaScript via an embedded iframe. The JavaScript will download the payload which will either be Locky or Trickybot.”

Just don’t open email from people or sites you are not familiar with
Many of us get emails from sites we are not sure of or people who claim to know who we are. Symantec has several precautions we should take to stay protected from ransomware and other cyberattacks.
1. Delete any emails you receive that look suspicious, especially if they contain links or attachments.
2. Always keep security software up to date to protect yourself against any new viruses or variants of malware.
3. Keep your operating system (OS) and other software updated. Software updates often include patches for newly discovered security vulnerabilities that could be exploited by attackers.
4. Make a habit of backing up any files stored on your computer. If your computer does become infected with ransomware, any files can be restored once the malware has been removed.

Avatar photo
Written By

We are deeply saddened to announce the passing of our dear friend Karen Graham, who served as Editor-at-Large at Digital Journal. She was 78 years old. Karen's view of what is happening in our world was colored by her love of history and how the past influences events taking place today. Her belief in humankind's part in the care of the planet and our environment has led her to focus on the need for action in dealing with climate change. It was said by Geoffrey C. Ward, "Journalism is merely history's first draft." Everyone who writes about what is happening today is indeed, writing a small part of our history.

You may also like:

Tech & Science

Microsoft and Google drubbed quarterly earnings expectations.

Tech & Science

The groundbreaking initiative aims to provide job training and confidence to people with autism.

Business

Catherine Berthet (L) and Naoise Ryan (R) join relatives of people killed in the Ethiopian Airlines Flight 302 Boeing 737 MAX crash at a...

Business

There is no statutory immunity. There never was any immunity. Move on.