Skip to content
Malware family

DanBot

DanBot is a backdoor associated with the Lyceum threat group.

Profile source: Mallory opens in a new tab

DanBot

Family profile

DanBot is a backdoor associated with the Lyceum threat group. It has been delivered via spearphishing emails containing malicious Excel attachments and relies on victim interaction to execute, including opening the malicious file. The malware can use a VBA macro embedded in an Excel file to drop its payload and can establish installation or persistence through a scheduled task. DanBot samples have been named UltraVNC.exe and WINVNC.exe to masquerade as legitimate VNC tools. Reported capabilities include uploading files from compromised hosts. The provided content identifies DanBot as one of the major tools attributed to Lyceum, alongside the Shark, Milan, and Marlin backdoors.

Reported operators

Threat actors

2 named in public reporting
OilRig

Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...

HEXANE

Major tools we attribute to Lyceum include DanBot, the Shark, Milan, and Marlin backdoors...

MITRE ATT&CK

DanBot in ATT&CK

19 distinct techniques

Reporting

Research mentioning DanBot

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.