logo

Botnet Ransomware will Screengrab your Desktop

ID: 939095b6-eedb-56c6-8160-fdf84cecb3d9

STIX ID: report--939095b6-eedb-56c6-8160-fdf84cecb3d9

Feed Name: Binary Defense Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Researchers observed a revival of the Necurs botnet sending millions of phishing emails that deliver a JavaScript downloader which installs Locky ransomware or Trickbot; the downloader also executes a PowerShell script to take screenshots and send operational data back to remote servers. Users are advised to keep systems updated to mitigate this active, large-scale malicious campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.