216.73.217.22

Danabot: Analyzing a fallen empire

· Published 25/05/2025 17:47 · Modified 26/05/2025 09:44

Export JSON

Essential information

Published
25/05/2025 17:47
Modified
26/05/2025 09:44
Tags
2025-05-23 2025-05-25 banking trojan botnet buran c&c infrastructure crisis cybercrime danabot darkgate data theft infostealer latrodectus lockbit lumma stealer malware-as-a-service malware-as-service matanbuchus nonransomware proxy servers recordbreaker rescoms smokeloader systembc ursnif zloader
Related entities
1 observables, 1 intrusion sets (apt), 16 malware, 7 others

Description

ESET Research shares insights into , an recently disrupted by law enforcement. The malware, tracked since 2018, evolved from a to a versatile tool for and malware distribution. Operated as a , offered features like data stealing, keylogging, and remote control. Its infrastructure included C&C servers, an administration panel, and . Distribution methods varied from email spam to Google Ads misuse. The takedown operation involved multiple cybersecurity companies and law enforcement agencies, leading to the identification of individuals responsible for 's development and operations.

External references