Skip to content

DanaBot

DanaBot is a modular Windows banking trojan and malware-as-a-service platform first observed in 2018.

Profile source: Mallory opens in a new tab

DanaBot

Family profile

DanaBot is a modular Windows banking trojan and malware-as-a-service platform first observed in 2018. Initially associated with theft of banking credentials and fraud, it later evolved into a broader crimeware platform used for credential theft, keylogging, information stealing, remote access through VNC-related functionality, payload delivery, and establishment of initial access for follow-on operations including ransomware. It has also been observed delivering secondary malware and enabling downstream intrusion activity, making it both an infostealer and an access-enablement platform.

DanaBot is operated through an affiliate model in which core operators maintain the malware, management panels, and shared command-and-control infrastructure while affiliates conduct campaigns. Reporting has linked its operations and management infrastructure to Russia, and the malware has been used in activity affecting victims across dozens of countries. Victimology has included financial targets, government entities, universities, law firms, and users of online banking and email services. Countries repeatedly noted among impacted populations include the United States, Mexico, Brazil, Australia, and multiple European states.

Capabilities attributed to DanaBot include credential theft from browsers and other applications, keylogging, banking web injection, download-and-execute of additional payloads, process injection, persistence through service creation, and anti-analysis or stealth features. Some variants and campaigns have shown rootkit-style hiding behavior on older Windows systems. Operators and affiliates have used DanaBot to deploy additional malware families and, in some cases, to support follow-on ransomware activity. Separate reporting also documented use of DanaBot’s delivery mechanism to launch a second-stage HTTP flood tool in a DDoS operation during the 2022 war in Ukraine.

Observed delivery methods include spearphishing emails, malicious email attachments or links, HTML smuggling, and distribution through other malware loaders such as Brushaloader and PrivateLoader. DanaBot has also appeared in malicious software-crack ecosystems and trojanized software delivery chains. Campaigns have included geographically selective delivery, such as restricting payload access to Australian victims in one targeted operation against a Queensland government department.

DanaBot remains notable for combining classic banking-trojan tradecraft with flexible post-compromise utility. Its evolution from a banking-focused trojan into a multi-purpose criminal platform has made it relevant to both fraud investigations and broader intrusion-response efforts, especially where credential theft, malware staging, and ransomware precursor activity intersect.

Capabilities

  • Credential Theft
  • Ddos
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Initial Access
  • Keylogging
  • Persistence
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 12, 2026
Last activity
Sep 18, 2026
Feed role
C2
Host form
36 IP / 0 hostnames

Leading locations

  • US11
  • NL6
  • DE4
  • CA3
  • HK3
  • HR2
  • LT2
  • FI1
  • FR1
  • GB1
  • KH1
  • PL1

Leading providers

  • ZORN TECHNOLOGIES5
  • GLOBAL CONNECTIVITY SOLUTIONS LLP4
  • HostPapa4
  • A1 Hrvatska d.o.o.2
  • Alibaba (US) Technology Co., Ltd.2
  • B2 Net Solutions Inc.2

Infrastructure traits

  • Hosting 32

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
TA547

GandCrab aura également été propagé fin 2018 au cours de chaînes d’infection impliquant Dridex botnet ID 10202 et TA547, identifié par Proofpoint comme l’opérateur du cheval de Troie bancaire Danabot.

TA564

This threat actor typically targets Canada with false shipping lures, such as CanadaPost and DHL, and have attempted to deliver Ursnif, DanaBot, and Nymaim in the past.

TA578

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

TA544

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

TA571

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

SCULLY SPIDER

Following DanaBot's debut in May 2018, it quickly gained popularity due to its modular functionality supporting credit card theft, wire fraud, and exfiltration of cryptocurrency-related files.

Exploited software

Vulnerabilities linked to DanaBot

1 CVEs

MITRE ATT&CK

DanaBot in ATT&CK

100 distinct techniques

Techniques

100 techniques
T1204.002 Malicious File T1195 Supply Chain Compromise T1059 Command and Scripting Interpreter T1105 Ingress Tool Transfer T1555 Credentials from Password Stores T1195.001 Compromise Software Dependencies and Development Tools T1498 Network Denial of Service T1056 Input Capture T1204 User Execution T1005 Data from Local System T1218.011 Rundll32 T1014 Rootkit T1059.005 Visual Basic T1566.001 Spearphishing Attachment T1218.010 Regsvr32 T1566 Phishing T1057 Process Discovery T1564.001 Hidden Files and Directories T1027 Obfuscated Files or Information T1185 Browser Session Hijacking T1543.003 Windows Service T1055 Process Injection T1041 Exfiltration Over C2 Channel T1071.001 Web Protocols T1573 Encrypted Channel T1566.002 Spearphishing Link T1082 System Information Discovery T1078 Valid Accounts T1219 Remote Access Tools T1110.003 Password Spraying T1218 System Binary Proxy Execution T1528 Steal Application Access Token T1203 Exploitation for Client Execution T1027.002 Software Packing T1539 Steal Web Session Cookie T1056.003 Web Portal Capture T1071 Application Layer Protocol T1090.003 Multi-hop Proxy T1059.001 PowerShell T1133 External Remote Services T1027.006 HTML Smuggling T1090 Proxy T1560.001 Archive via Utility T1115 Clipboard Data T1113 Screen Capture T1003 OS Credential Dumping T1548 Abuse Elevation Control Mechanism T1587.001 Malware T1059.007 JavaScript T1056.001 Keylogging T1008 Fallback Channels T1586 Compromise Accounts T1548.002 Bypass User Account Control T1557 Adversary-in-the-Middle T1036 Masquerading T1583 Acquire Infrastructure T1125 Video Capture T1027.013 Encrypted/Encoded File T1027.007 Dynamic API Resolution T1598 Phishing for Information T1620 Reflective Code Loading T1497 Virtualization/Sandbox Evasion T1560 Archive Collected Data T1021 Remote Services T1189 Drive-by Compromise T1021.001 Remote Desktop Protocol T1497.001 System Checks T1021.005 VNC T1568 Dynamic Resolution T1083 File and Directory Discovery T1547.009 Shortcut Modification T1555.003 Credentials from Web Browsers T1560.003 Archive via Custom Method T1106 Native API T1571 Non-Standard Port T1560.002 Archive via Library T1656 Impersonation T1020 Automated Exfiltration T1204.001 Malicious Link T1583.008 Malvertising T1095 Non-Application Layer Protocol T1573.002 Asymmetric Cryptography T1608.001 Upload Malware T1001.001 Junk Data T1055.001 Dynamic-link Library Injection T1573.001 Symmetric Cryptography T1566.003 Spearphishing via Service T1030 Data Transfer Size Limits T1132.001 Standard Encoding T1218.007 Msiexec T1583.004 Server T1217 Browser Information Discovery T1583.003 Virtual Private Server T1010 Application Window Discovery T1119 Automated Collection T1486 Data Encrypted for Impact T1218.005 Mshta T1140 Deobfuscate/Decode Files or Information T1104 Multi-Stage Channels T1583.001 Domains

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.