Last seven days
- First activity
- Jul 19, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 6 IP / 5 hostnames
DanaBot is a modular banking Trojan and stealer written in Delphi, first publicly reported by Proofpoint in May 2018 after malicious email campaigns targeting users in Australia.
Profile source: Mallory opens in a new tabDanaBot
DanaBot is a modular banking Trojan and stealer written in Delphi, first publicly reported by Proofpoint in May 2018 after malicious email campaigns targeting users in Australia. It has operated as a malware-as-a-service platform used by multiple affiliates and was later linked by U.S. authorities to a Russia-based cybercrime organization. DanaBot has been distributed through spam emails with malicious attachments or hyperlinks, macro-enabled Word documents, zipped JavaScript downloaders, Brushaloader/BrushaLoader using PowerShell and VBS scripts, Hancitor-delivered chains, software cracks and warez sites, MSI loaders, and ClickFix-style campaigns on compromised or attacker-controlled websites. Reported delivery chains also include bundled deployment with other malware such as Pony variants, Xworm, SectopRAT/ArechClient, and a likely cryptocurrency miner.
DanaBot uses a multi-stage, multi-component architecture consisting of a loader, a main module, and plug-ins or modules. Across reporting, observed capabilities include banking webinjects and session hijacking, credential theft from browsers, FTP, VPN, chat, email, and other applications, theft of cookies, browsing history, device and system information, screenshots, file listings, cryptocurrency wallet information, keylogging, video recording of user activity, full remote access, VNC, SOCKS/proxy and sniffer functionality, TOR-based communications or C2 list updates, and an RDP plug-in based on RDPWrap. Proofpoint and ESET documented continued development, including a new encrypted C2 protocol introduced in late January 2019 using AES and RSA, changes to loader architecture, campaign IDs, 64-bit stealer support, and additional remote-access functionality.
Targeting documented in the content includes Australia, Poland, Italy, Germany, Austria, Ukraine, the United States, Canada, the United Kingdom, Mexico, and broader Europe and North America. Campaigns targeted banking portals, webmail services, cryptocurrency-related files and processes, and in Ukraine also corporate banking software and remote access tools. Reporting also notes DanaBot activity and victim prevalence in Mexico in 2025. U.S. authorities stated that one DanaBot variant was used for fraud and credential theft, while a second variant targeted military, diplomatic, government, law enforcement, and related entities in North America and Europe, recording victim interactions and sending stolen data to separate servers.
The malware has been associated with multiple threat actors and ecosystems. Proofpoint initially attributed early Australian distribution to TA547 and later assessed DanaBot was used by multiple affiliates. BrushaLoader was strongly linked to DanaBot affiliate ID 3, and other reporting described DanaBot as used by multiple carding gangs rather than a single actor. Law enforcement actions under Operation Endgame disrupted DanaBot infrastructure, and by May 2025 the DanaBot network was reported dismantled with charges against 16 people. The U.S. Department of Justice stated DanaBot infected more than 300,000 computers worldwide and caused at least $50 million in damage.
High-confidence indicators mentioned in the content include C2 or related infrastructure such as 84.54.37[.]102, 89.144.25[.]243, 89.144.25[.]104, 178.209.51[.]211, 185.92.222[.]238, 192.71.249[.]51, 149.154.152.64, 149.154.157.220, 158.255.215.31, 178.209.51.227, 37.235.53.232, 45.77.231.138, 45.77.51.69, 45.77.54.180, 45.77.96.198, 95.179.151.252, 23.226.132.92, 23.106.123.249, 108.62.141.152, 104.144.64.163, and TOR hostnames y7zmcwurl6nphcve.onion and 5jjsgjephjcua63go2o5donzw5x4hiwn6wh2dennmyq65pbhk6qflzyd.onion. Additional URLs and domains tied to delivery or related activity include hxxp://bbc[.]lumpens[.]org/tXBDQjBLvs.php, hxxp://members[.]giftera[.]org/whuBcaJpqg.php, hxxp://45.147.230.58/palata.exe, eressedn27.top, morttttq12.top, and attacker-controlled lure domains such as antigravity[.]study. Sample hashes explicitly mentioned include c0eb802f394e758da4feb0d6c3b817bf1f64880ab9bc851937d5ef774161585d and 8327931a5d2430526862d789b9654c9c8da7bc64519d210a93e4720aac7ccaa0.
C2 tracking
Derp observations, rolling seven-day window
Samples
0a4aeb4dd0aa51ddbf5be869e05ca9cd3670d66d3ec43889c42cf32d791f2c27 7123e1514b939b165985560057fe3c761440a9fff9783a3b84e861fd2888d4ab 1ea8d905d88e87ced611545a34041af86292f555e0f5a3ae9648dbb76286983e 3b43e8f01b1f456a2e3d0cf507a28f57eede64c5a477be7db17685c6a3f8fb3e 80528e16c3d9e33bda933a88fd034d2a683f339778255a3006ea7828b4370675 13ea8f098dd1022638e9e5bbebb88bed19b02359bbb748bd2e1f37710ee876c3 1a94fa908531476ddfc994b311c58b632226ffd25088cd39442692edd4a98b42 2c28b6c2f02f16ae8508131ffafa60d346d12f6190dccd49d435f2ca94e88133 5ce5a13b620a10bcf7a0486743592d8fd3af88ebbbadfe1995ff3954ac317e09 7d3654531c32d941b8cae81c4137fc542172bfa9635f169cb392f245a0a12bcb Reported operators
Proofpoint researchers discovered a new banking Trojan, dubbed “DanaBot”, targeting users in Australia via emails containing malicious URLs.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Following DanaBot's debut in May 2018, it quickly gained popularity due to its modular functionality supporting credit card theft, wire fraud, and exfiltration of cryptocurrency-related files.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Storm-1044 Financially motivated Danabot
MITRE ATT&CK
Reporting
DanaBot2
Bundled Xworm, dropped by DanaBot (Related) — Co-delivered/loader malware
In 2025, AsyncRAT, DanaBot, and KV-Botnet were the top three malware families, respectively, based on the number of unique victims, and DanaBot, Beavertail, and LummaC2 led in observed infections in Mexico.
The disruption is the latest phase of Operation Endgame, which previously disrupted other malware families, such as DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader.
A year ago, ESET Research was part of two major operations that disrupted some of the leading cybercriminal operations at the time, Lumma Stealer and Danabot.
Также в прошлые годы операция затрагивала инфраструктуру SmokeLoader, DanaBot, IcedID, Pikabot, Trickbot, Bumblebee, SystemBC...
by May 2025, the DanaBot network was dismantled, leading to charges against 16 people
Previously, Operation Endgame has also targeted ransomware infrastructure, Smokeloader botnet customers and servers, the AVCheck site, and various other major malware operations, including DanaBot, IcedID, Pikabot, Trickbot, Smokeloader, Bumblebee, and SystemBC.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.