Proofpoint researchers discovered a new banking Trojan, dubbed “DanaBot”, targeting users in Australia via emails containing malicious URLs.
DanaBot
DanaBot is a modular Delphi-based banking Trojan and malware-as-a-service platform first publicly documented in 2018.
Profile source: Mallory opens in a new tabDanaBot
Family profile
DanaBot is a modular Delphi-based banking Trojan and malware-as-a-service platform first publicly documented in 2018. Initially observed in campaigns targeting Australia, it later expanded to Europe, North America, Latin America, and other regions through multiple affiliate-driven operations. The malware evolved from a banking-focused threat into a broader crimeware platform used for credential theft, banking-session hijacking, remote access, surveillance, and delivery of additional payloads, including ransomware and other malware families.
DanaBot uses a multi-component architecture with a loader, a main module, and plug-ins that extend functionality. Reported capabilities include theft of browser and application credentials, collection of financial and device information, browsing-history theft, cryptocurrency-wallet targeting, keylogging, screenshot and video capture, and full remote control of infected systems. Documented plug-ins and features have included VNC-based remote access, proxying and traffic interception, browser injection for banking fraud, TOR-assisted infrastructure updates, RDP enablement, and support for downloading and executing follow-on malware. Later versions introduced more sophisticated encrypted command-and-control protocols and architectural changes intended to hinder network detection and analysis.
Distribution has most commonly relied on malicious email campaigns using attachments or links, including invoice- and document-themed lures, often with intermediary loaders or scripts. Additional observed delivery methods have included cracked-software and warez ecosystems, as well as more recent ClickFix-style social-engineering chains in which DanaBot was delivered by another loader. DanaBot has also been observed as a secondary payload delivered by other malware such as Hancitor and in bundled infections alongside other remote-access malware.
The malware has been associated with a broad cybercriminal ecosystem rather than a single operator. Reporting has consistently described an affiliate model with shared tooling or backend services, and law-enforcement actions have characterized it as a Russia-based cybercrime operation. DanaBot has been used in financially motivated campaigns against banks, fintechs, businesses, and consumers, and a separate variant was reportedly used to target government, diplomatic, military, and law-enforcement-related entities in North America and Europe. International disruption efforts under Operation Endgame and related law-enforcement actions have targeted DanaBot infrastructure and operators, reflecting its significance as a long-running botnet and banking-malware ecosystem.
Capabilities
- Credential Theft
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Initial Access
- Keylogging
- Persistence
- Post Exploitation
- Session Hijacking
- Spoofing
Reported operators
Threat actors
7 named in public reportingProofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Following DanaBot's debut in May 2018, it quickly gained popularity due to its modular functionality supporting credit card theft, wire fraud, and exfiltration of cryptocurrency-related files.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Storm-1044 Financially motivated Danabot
MITRE ATT&CK