This presentation will include the latest research on the Necurs botnet which has historically spammed lures for Locky ransomware, Dridex banking trojan, and most recently, Jaff ransomware . Paul has been monitoring this botnet for over two years and will discuss the history, infrastructure, and threat actors behind this Crimeware as a Service (CaaS) offering.