Categories: CyberCrimeSecurity

Necurs Botnet Targets Users With Old-School Stock Scam

A well-known botnet appears to have woken up from a recent slumber, prompting a significant rise in the global amount of spam being sent out.

According to researchers at Sophos’ Naked Security, the global volume of spam dropped by more than half just before Christmas and continued to stay at around the same level, believed to be due to the notorious Necurs botnet going quiet.

Researcher Paul Ducklin suggested that the criminals behind the botnet had knowingly taken it offline “for an as-yet unknown reason that could range anywhere from going on vacation to lying low from law enforcement or some rival gang”.

Stock scam

However, this week the spam volume jumped back up to approximately half the level of the pre-Christmas peaks and five times higher than the “background spam rate”, suggesting that Necurs is up and running again.

The new scam being sent out is called a ‘pump-and-dump,’ one that hasn’t been seen for some time due to its relative ineffectiveness compared to other scams such as phishing emails containing malicious attachments that have generated huge sums of money for cyber crooks.

Instead, Ducklin explained, the scammers try to persuade their targets into buying shares by advertising a ‘once-in-a-lifetime’ opportunity for an obscure stock, which in this case was for a media company called InCapta, Inc (INCT).

“The theory is that if you pick a cheap stock, concoct a believable story to talk it up, and buy in just before your victims start receiving their emails then your initial bulk purchase will push the stock up a bit, add veracity to your claims that the stock will soon be flying, and encourage more and more victims to buy into the scam, pumping up the stock further and further.”

The scammers will then sell their stock for a hefty profit, while the victims are left with their own shares which will likely decrease back down to their original value.

Ducklin’s advice is to always ignore unsolicited bulk emails that swear you to secrecy and warns that if it sounds too good to be true, then it probably is.

Quiz: Cyber security in 2017

Sam Pudwell

Sam Pudwell joined Silicon UK as a reporter in December 2016. As well as being the resident Cloud aficionado, he covers areas such as cyber security, government IT and sports technology, with the aim of going to as many events as possible.

Recent Posts

London Black Cabs Sue Uber In Latest Legal Tangle

More than 10,000 London black cab drivers sue Uber claiming company acted illegally to obtain…

17 mins ago

Electric Vehicle Turned Away From Hospital Car Park

Liverpool's Alder Hey children's hospital turns away electric car from car park due to 'fire…

47 mins ago

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

3 days ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

3 days ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

3 days ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

4 days ago