Danabot: Analyzing a fallen empire
Essential information
- Published
- 25/05/2025 17:47
- Modified
- 26/05/2025 09:44
- Tags
- 2025-05-23 2025-05-25 banking trojan botnet buran c&c infrastructure crisis cybercrime danabot darkgate data theft infostealer latrodectus lockbit lumma stealer malware-as-a-service malware-as-service matanbuchus nonransomware proxy servers recordbreaker rescoms smokeloader systembc ursnif zloader
- Related entities
- 1 observables, 1 intrusion sets (apt), 16 malware, 7 others
Description
ESET Research shares insights into Danabot, an infostealer recently disrupted by law enforcement. The malware, tracked since 2018, evolved from a banking trojan to a versatile tool for data theft and malware distribution. Operated as a malware-as-a-service, Danabot offered features like data stealing, keylogging, and remote control. Its infrastructure included C&C servers, an administration panel, and proxy servers. Distribution methods varied from email spam to Google Ads misuse. The takedown operation involved multiple cybersecurity companies and law enforcement agencies, leading to the identification of individuals responsible for Danabot's development and operations.