Skip to content

DanaBot

DanaBot is a modular Delphi-based banking Trojan and malware-as-a-service platform first publicly documented in 2018.

Profile source: Mallory opens in a new tab

DanaBot

Family profile

DanaBot is a modular Delphi-based banking Trojan and malware-as-a-service platform first publicly documented in 2018. Initially observed in campaigns targeting Australia, it later expanded to Europe, North America, Latin America, and other regions through multiple affiliate-driven operations. The malware evolved from a banking-focused threat into a broader crimeware platform used for credential theft, banking-session hijacking, remote access, surveillance, and delivery of additional payloads, including ransomware and other malware families.

DanaBot uses a multi-component architecture with a loader, a main module, and plug-ins that extend functionality. Reported capabilities include theft of browser and application credentials, collection of financial and device information, browsing-history theft, cryptocurrency-wallet targeting, keylogging, screenshot and video capture, and full remote control of infected systems. Documented plug-ins and features have included VNC-based remote access, proxying and traffic interception, browser injection for banking fraud, TOR-assisted infrastructure updates, RDP enablement, and support for downloading and executing follow-on malware. Later versions introduced more sophisticated encrypted command-and-control protocols and architectural changes intended to hinder network detection and analysis.

Distribution has most commonly relied on malicious email campaigns using attachments or links, including invoice- and document-themed lures, often with intermediary loaders or scripts. Additional observed delivery methods have included cracked-software and warez ecosystems, as well as more recent ClickFix-style social-engineering chains in which DanaBot was delivered by another loader. DanaBot has also been observed as a secondary payload delivered by other malware such as Hancitor and in bundled infections alongside other remote-access malware.

The malware has been associated with a broad cybercriminal ecosystem rather than a single operator. Reporting has consistently described an affiliate model with shared tooling or backend services, and law-enforcement actions have characterized it as a Russia-based cybercrime operation. DanaBot has been used in financially motivated campaigns against banks, fintechs, businesses, and consumers, and a separate variant was reportedly used to target government, diplomatic, military, and law-enforcement-related entities in North America and Europe. International disruption efforts under Operation Endgame and related law-enforcement actions have targeted DanaBot infrastructure and operators, reflecting its significance as a long-running botnet and banking-malware ecosystem.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Initial Access
  • Keylogging
  • Persistence
  • Post Exploitation
  • Session Hijacking
  • Spoofing

Reported operators

Threat actors

7 named in public reporting
TA547

Proofpoint researchers discovered a new banking Trojan, dubbed “DanaBot”, targeting users in Australia via emails containing malicious URLs.

TA578

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

TA544

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

TA571

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

SCULLY SPIDER

Following DanaBot's debut in May 2018, it quickly gained popularity due to its modular functionality supporting credit card theft, wire fraud, and exfiltration of cryptocurrency-related files.

TA564

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

MITRE ATT&CK

DanaBot in ATT&CK

78 distinct techniques

Techniques

78 techniques
T1082 System Information Discovery T1566.001 Spearphishing Attachment T1539 Steal Web Session Cookie T1105 Ingress Tool Transfer T1059 Command and Scripting Interpreter T1566 Phishing T1189 Drive-by Compromise T1056.001 Keylogging T1059.001 PowerShell T1566.002 Spearphishing Link T1036 Masquerading T1021.001 Remote Desktop Protocol T1005 Data from Local System T1497.001 System Checks T1021.005 VNC T1059.005 Visual Basic T1090.003 Multi-hop Proxy T1568 Dynamic Resolution T1555 Credentials from Password Stores T1219 Remote Access Tools T1056.003 Web Portal Capture T1071 Application Layer Protocol T1113 Screen Capture T1083 File and Directory Discovery T1041 Exfiltration Over C2 Channel T1573 Encrypted Channel T1543.003 Windows Service T1090 Proxy T1185 Browser Session Hijacking T1027 Obfuscated Files or Information T1125 Video Capture T1560 Archive Collected Data T1547.009 Shortcut Modification T1027.007 Dynamic API Resolution T1555.003 Credentials from Web Browsers T1055 Process Injection T1059.007 JavaScript T1204.002 Malicious File T1204 User Execution T1586 Compromise Accounts T1548.002 Bypass User Account Control T1560.003 Archive via Custom Method T1195 Supply Chain Compromise T1218.011 Rundll32 T1218.010 Regsvr32 T1106 Native API T1571 Non-Standard Port T1560.002 Archive via Library T1656 Impersonation T1587.001 Malware T1020 Automated Exfiltration T1204.001 Malicious Link T1583.008 Malvertising T1057 Process Discovery T1095 Non-Application Layer Protocol T1573.002 Asymmetric Cryptography T1608.001 Upload Malware T1001.001 Junk Data T1498 Network Denial of Service T1008 Fallback Channels T1055.001 Dynamic-link Library Injection T1573.001 Symmetric Cryptography T1566.003 Spearphishing via Service T1030 Data Transfer Size Limits T1132.001 Standard Encoding T1218.007 Msiexec T1583.004 Server T1217 Browser Information Discovery T1583.003 Virtual Private Server T1010 Application Window Discovery T1119 Automated Collection T1115 Clipboard Data T1486 Data Encrypted for Impact T1218.005 Mshta T1140 Deobfuscate/Decode Files or Information T1104 Multi-Stage Channels T1583.001 Domains T1056 Input Capture

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.