Skip to content
Malware family

DanaBot

DanaBot is a modular banking Trojan and stealer written in Delphi, first publicly reported by Proofpoint in May 2018 after malicious email campaigns targeting users in Australia.

Profile source: Mallory opens in a new tab

DanaBot

Family profile

DanaBot is a modular banking Trojan and stealer written in Delphi, first publicly reported by Proofpoint in May 2018 after malicious email campaigns targeting users in Australia. It has operated as a malware-as-a-service platform used by multiple affiliates and was later linked by U.S. authorities to a Russia-based cybercrime organization. DanaBot has been distributed through spam emails with malicious attachments or hyperlinks, macro-enabled Word documents, zipped JavaScript downloaders, Brushaloader/BrushaLoader using PowerShell and VBS scripts, Hancitor-delivered chains, software cracks and warez sites, MSI loaders, and ClickFix-style campaigns on compromised or attacker-controlled websites. Reported delivery chains also include bundled deployment with other malware such as Pony variants, Xworm, SectopRAT/ArechClient, and a likely cryptocurrency miner.

DanaBot uses a multi-stage, multi-component architecture consisting of a loader, a main module, and plug-ins or modules. Across reporting, observed capabilities include banking webinjects and session hijacking, credential theft from browsers, FTP, VPN, chat, email, and other applications, theft of cookies, browsing history, device and system information, screenshots, file listings, cryptocurrency wallet information, keylogging, video recording of user activity, full remote access, VNC, SOCKS/proxy and sniffer functionality, TOR-based communications or C2 list updates, and an RDP plug-in based on RDPWrap. Proofpoint and ESET documented continued development, including a new encrypted C2 protocol introduced in late January 2019 using AES and RSA, changes to loader architecture, campaign IDs, 64-bit stealer support, and additional remote-access functionality.

Targeting documented in the content includes Australia, Poland, Italy, Germany, Austria, Ukraine, the United States, Canada, the United Kingdom, Mexico, and broader Europe and North America. Campaigns targeted banking portals, webmail services, cryptocurrency-related files and processes, and in Ukraine also corporate banking software and remote access tools. Reporting also notes DanaBot activity and victim prevalence in Mexico in 2025. U.S. authorities stated that one DanaBot variant was used for fraud and credential theft, while a second variant targeted military, diplomatic, government, law enforcement, and related entities in North America and Europe, recording victim interactions and sending stolen data to separate servers.

The malware has been associated with multiple threat actors and ecosystems. Proofpoint initially attributed early Australian distribution to TA547 and later assessed DanaBot was used by multiple affiliates. BrushaLoader was strongly linked to DanaBot affiliate ID 3, and other reporting described DanaBot as used by multiple carding gangs rather than a single actor. Law enforcement actions under Operation Endgame disrupted DanaBot infrastructure, and by May 2025 the DanaBot network was reported dismantled with charges against 16 people. The U.S. Department of Justice stated DanaBot infected more than 300,000 computers worldwide and caused at least $50 million in damage.

High-confidence indicators mentioned in the content include C2 or related infrastructure such as 84.54.37[.]102, 89.144.25[.]243, 89.144.25[.]104, 178.209.51[.]211, 185.92.222[.]238, 192.71.249[.]51, 149.154.152.64, 149.154.157.220, 158.255.215.31, 178.209.51.227, 37.235.53.232, 45.77.231.138, 45.77.51.69, 45.77.54.180, 45.77.96.198, 95.179.151.252, 23.226.132.92, 23.106.123.249, 108.62.141.152, 104.144.64.163, and TOR hostnames y7zmcwurl6nphcve.onion and 5jjsgjephjcua63go2o5donzw5x4hiwn6wh2dennmyq65pbhk6qflzyd.onion. Additional URLs and domains tied to delivery or related activity include hxxp://bbc[.]lumpens[.]org/tXBDQjBLvs.php, hxxp://members[.]giftera[.]org/whuBcaJpqg.php, hxxp://45.147.230.58/palata.exe, eressedn27.top, morttttq12.top, and attacker-controlled lure domains such as antigravity[.]study. Sample hashes explicitly mentioned include c0eb802f394e758da4feb0d6c3b817bf1f64880ab9bc851937d5ef774161585d and 8327931a5d2430526862d789b9654c9c8da7bc64519d210a93e4720aac7ccaa0.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 19, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
6 IP / 5 hostnames

Leading locations

  • US3
  • FR2
  • CA1
  • HR1

Leading providers

  • OVH SAS3
  • A1 Hrvatska d.o.o.1
  • Cloudflare, Inc.1
  • Cogent Communications, LLC1
  • HIVELOCITY, Inc.1

Infrastructure traits

  • Hosting 5
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

7 named in public reporting
TA547

Proofpoint researchers discovered a new banking Trojan, dubbed “DanaBot”, targeting users in Australia via emails containing malicious URLs.

TA578

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

TA544

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

TA571

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

SCULLY SPIDER

Following DanaBot's debut in May 2018, it quickly gained popularity due to its modular functionality supporting credit card theft, wire fraud, and exfiltration of cryptocurrency-related files.

TA564

Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.

MITRE ATT&CK

DanaBot in ATT&CK

78 distinct techniques

Techniques

78 techniques
T1059.001 PowerShell T1566.002 Spearphishing Link T1036 Masquerading T1021.001 Remote Desktop Protocol T1005 Data from Local System T1497.001 System Checks T1021.005 VNC T1566.001 Spearphishing Attachment T1059.005 Visual Basic T1090.003 Multi-hop Proxy T1568 Dynamic Resolution T1555 Credentials from Password Stores T1219 Remote Access Tools T1056.003 Web Portal Capture T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1566 Phishing T1113 Screen Capture T1082 System Information Discovery T1083 File and Directory Discovery T1041 Exfiltration Over C2 Channel T1573 Encrypted Channel T1543.003 Windows Service T1090 Proxy T1185 Browser Session Hijacking T1027 Obfuscated Files or Information T1125 Video Capture T1056.001 Keylogging T1059 Command and Scripting Interpreter T1560 Archive Collected Data T1539 Steal Web Session Cookie T1547.009 Shortcut Modification T1027.007 Dynamic API Resolution T1555.003 Credentials from Web Browsers T1055 Process Injection T1059.007 JavaScript T1204.002 Malicious File T1204 User Execution T1189 Drive-by Compromise T1586 Compromise Accounts T1548.002 Bypass User Account Control T1560.003 Archive via Custom Method T1195 Supply Chain Compromise T1218.011 Rundll32 T1218.010 Regsvr32 T1106 Native API T1571 Non-Standard Port T1560.002 Archive via Library T1656 Impersonation T1587.001 Malware T1020 Automated Exfiltration T1204.001 Malicious Link T1583.008 Malvertising T1057 Process Discovery T1095 Non-Application Layer Protocol T1573.002 Asymmetric Cryptography T1608.001 Upload Malware T1001.001 Junk Data T1498 Network Denial of Service T1008 Fallback Channels T1055.001 Dynamic-link Library Injection T1573.001 Symmetric Cryptography T1566.003 Spearphishing via Service T1030 Data Transfer Size Limits T1132.001 Standard Encoding T1218.007 Msiexec T1583.004 Server T1217 Browser Information Discovery T1583.003 Virtual Private Server T1010 Application Window Discovery T1119 Automated Collection T1115 Clipboard Data T1486 Data Encrypted for Impact T1218.005 Mshta T1140 Deobfuscate/Decode Files or Information T1104 Multi-Stage Channels T1583.001 Domains T1056 Input Capture

Reporting

Research mentioning DanaBot

Jul 7
Gurucul Threat Research

Millenium: A RAT Rewritten, a Threat Multiplied | Community Portal | Gurucul

DanaBot2

Jun 26
Osint Team

The Thieves Who Skip Your Password and Your Two-Factor Code | by Pop123 | Jun, 2026 | OSINT Team

Bundled Xworm, dropped by DanaBot (Related) — Co-delivered/loader malware

Jun 25
Recorded Future

Evaluating Mexico’s New Cybersecurity Plan

In 2025, AsyncRAT, DanaBot, and KV-Botnet were the top three malware families, respectively, based on the number of unique victims, and DanaBot, Beavertail, and LummaC2 led in observed infections in Mexico.

Jun 24
Bleeping Computer

Amadey, StealC malware operations disrupted in Operation Endgame action

The disruption is the latest phase of Operation Endgame, which previously disrupted other malware families, such as DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader.

Jun 24
Eset Welivesecurity

ESET takes part in Operation Endgame to disrupt Amadey and Stealc

A year ago, ESET Research was part of two major operations that disrupted some of the leading cybercriminal operations at the time, Lumma Stealer and Danabot.

Jun 22
Xakep

Правоохранители очистили 15 000 сайтов, зараженных SocGholish - Хакер

Также в прошлые годы операция затрагивала инфраструктуру SmokeLoader, DanaBot, IcedID, Pikabot, Trickbot, Bumblebee, SystemBC...

Jun 18
Hackread

Operation Endgame Disrupts SocGholish Malware Infrastructure

by May 2025, the DanaBot network was dismantled, leading to charges against 16 people

Jun 18
Bleeping Computer

Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp

Previously, Operation Endgame has also targeted ransomware infrastructure, Smokeloader botnet customers and servers, the AVCheck site, and various other major malware operations, including DanaBot, IcedID, Pikabot, Trickbot, Smokeloader, Bumblebee, and SystemBC.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.