Botnet Ransomware will Screengrab your Desktop
ID: 939095b6-eedb-56c6-8160-fdf84cecb3d9
STIX ID: report--939095b6-eedb-56c6-8160-fdf84cecb3d9
Feed Name: Binary Defense Blog
Threat Score
Researchers observed a revival of the Necurs botnet sending millions of phishing emails that deliver a JavaScript downloader which installs Locky ransomware or Trickbot; the downloader also executes a PowerShell script to take screenshots and send operational data back to remote servers. Users are advised to keep systems updated to mitigate this active, large-scale malicious campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
