TheNecurs botnet is a distributor of many pieces of malware, most notablyLocky.
Around June 1, 2016, thebotnet went offline, perhaps due to aglitch in thecommand and control server running Necurs. However, three weeks later, Jon French fromAppRiver discovered a spike inspam emails, signifying either a temporary spike in the botnet's activity or return to its normal pre-June 1 state.[1][2]
In a 2020 report, it was noted to have particularly targeted India, Southeast Asia, Turkey and Mexico.[3]
Source:[4]