Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Gold Riverview, Spandex Tempest, CHIMBORAZO
Necurs emerged in 2012 as an infector and rootkit, and quickly partnered with elite cybercrime gangs to become part of the top spamming and infection forces in the malware realm. Unlike most botnets, Necurs stands out due to its technical complexity, partnership diversity and continued evolution in an era when even the most complex malicious infrastructures can no longer withstand disruption. In the past year alone, we have seen Necurs take on various roles. Linked with the spam distribution of the Dridex gang, it is used to spread one of the world’s most nefarious banking Trojans. It also moved to mass distributing Locky, Dridex’s ransomware child, then added distributed denial-of-service (DDoS) attacks. Most recently, Necurs moved to pump-and-dump stock scam distribution before returning to spreading millions of Dridex-laden spam emails a day. Necurs has been observed to distribute Dridex ( Indrik Spider ) Locky ( Dungeon Spider ), TrickBot ( Wizard Spider, Gold Blackburn ) and much of the malware from TA505, Graceful Spider, Gold Evergreen .
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database