Last seven days
- First activity
- Sep 12, 2026
- Last activity
- Sep 18, 2026
- Feed role
- C2
- Host form
- 36 IP / 0 hostnames
DanaBot is a modular Windows banking trojan and malware-as-a-service platform first observed in 2018.
Profile source: Mallory opens in a new tabDanaBot
DanaBot is a modular Windows banking trojan and malware-as-a-service platform first observed in 2018. Initially associated with theft of banking credentials and fraud, it later evolved into a broader crimeware platform used for credential theft, keylogging, information stealing, remote access through VNC-related functionality, payload delivery, and establishment of initial access for follow-on operations including ransomware. It has also been observed delivering secondary malware and enabling downstream intrusion activity, making it both an infostealer and an access-enablement platform.
DanaBot is operated through an affiliate model in which core operators maintain the malware, management panels, and shared command-and-control infrastructure while affiliates conduct campaigns. Reporting has linked its operations and management infrastructure to Russia, and the malware has been used in activity affecting victims across dozens of countries. Victimology has included financial targets, government entities, universities, law firms, and users of online banking and email services. Countries repeatedly noted among impacted populations include the United States, Mexico, Brazil, Australia, and multiple European states.
Capabilities attributed to DanaBot include credential theft from browsers and other applications, keylogging, banking web injection, download-and-execute of additional payloads, process injection, persistence through service creation, and anti-analysis or stealth features. Some variants and campaigns have shown rootkit-style hiding behavior on older Windows systems. Operators and affiliates have used DanaBot to deploy additional malware families and, in some cases, to support follow-on ransomware activity. Separate reporting also documented use of DanaBot’s delivery mechanism to launch a second-stage HTTP flood tool in a DDoS operation during the 2022 war in Ukraine.
Observed delivery methods include spearphishing emails, malicious email attachments or links, HTML smuggling, and distribution through other malware loaders such as Brushaloader and PrivateLoader. DanaBot has also appeared in malicious software-crack ecosystems and trojanized software delivery chains. Campaigns have included geographically selective delivery, such as restricting payload access to Australian victims in one targeted operation against a Queensland government department.
DanaBot remains notable for combining classic banking-trojan tradecraft with flexible post-compromise utility. Its evolution from a banking-focused trojan into a multi-purpose criminal platform has made it relevant to both fraud investigations and broader intrusion-response efforts, especially where credential theft, malware staging, and ransomware precursor activity intersect.
C2 tracking
Derp observations, rolling seven-day window
Samples
e2403895e1b0de018b14073e209d08c326205b6d7615a03755fcca5baafe7446 a41d5274599dfe60823b477ea0dc20b9c8e9b398d8b287701f8cb02ea605ad84 a238a290fdfc0ff3988c54503cfce9392a2859922ef9f01309470cff92152b7c 90aecdab83b014e229ccb44d1747f4cdb0e291a5656ada80c8d72311b81ce591 3052c6e24679896c767fccbe202db8604120adfd57f3b02a72013476c926514b 500462c4fb6e4d0545f04d63ef981d9611b578948e5cfd61d840ff8e2f206587 28d446af80937f858098c4496863123c26f74ed3ca6ccc0d6fb3682a7ff64156 88d82df599a0e7cd21f8e98b717c7365544800d3c466ad8deb8020d2ed488b55 Reported operators
GandCrab aura également été propagé fin 2018 au cours de chaînes d’infection impliquant Dridex botnet ID 10202 et TA547, identifié par Proofpoint comme l’opérateur du cheval de Troie bancaire Danabot.
This threat actor typically targets Canada with false shipping lures, such as CanadaPost and DHL, and have attempted to deliver Ursnif, DanaBot, and Nymaim in the past.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Following DanaBot's debut in May 2018, it quickly gained popularity due to its modular functionality supporting credit card theft, wire fraud, and exfiltration of cryptocurrency-related files.
Storm-1044 Financially motivated Danabot
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.