Categories: CyberCrimeSecurity

Necurs Botnet Targets Users With Old-School Stock Scam

A well-known botnet appears to have woken up from a recent slumber, prompting a significant rise in the global amount of spam being sent out.

According to researchers at Sophos’ Naked Security, the global volume of spam dropped by more than half just before Christmas and continued to stay at around the same level, believed to be due to the notorious Necurs botnet going quiet.

Researcher Paul Ducklin suggested that the criminals behind the botnet had knowingly taken it offline “for an as-yet unknown reason that could range anywhere from going on vacation to lying low from law enforcement or some rival gang”.

Stock scam

However, this week the spam volume jumped back up to approximately half the level of the pre-Christmas peaks and five times higher than the “background spam rate”, suggesting that Necurs is up and running again.

The new scam being sent out is called a ‘pump-and-dump,’ one that hasn’t been seen for some time due to its relative ineffectiveness compared to other scams such as phishing emails containing malicious attachments that have generated huge sums of money for cyber crooks.

Instead, Ducklin explained, the scammers try to persuade their targets into buying shares by advertising a ‘once-in-a-lifetime’ opportunity for an obscure stock, which in this case was for a media company called InCapta, Inc (INCT).

“The theory is that if you pick a cheap stock, concoct a believable story to talk it up, and buy in just before your victims start receiving their emails then your initial bulk purchase will push the stock up a bit, add veracity to your claims that the stock will soon be flying, and encourage more and more victims to buy into the scam, pumping up the stock further and further.”

The scammers will then sell their stock for a hefty profit, while the victims are left with their own shares which will likely decrease back down to their original value.

Ducklin’s advice is to always ignore unsolicited bulk emails that swear you to secrecy and warns that if it sounds too good to be true, then it probably is.

Quiz: Cyber security in 2017

Sam Pudwell

Sam Pudwell joined Silicon UK as a reporter in December 2016. As well as being the resident Cloud aficionado, he covers areas such as cyber security, government IT and sports technology, with the aim of going to as many events as possible.

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago