216.73.217.22

DanaBot C2 Server Memory Leak Bug

· Published 10/06/2025 05:10 · Modified 10/06/2025 09:10

Export JSON

Essential information

Published
10/06/2025 05:10
Modified
10/06/2025 09:10
Tags
2025-06-10 banking fraud c2 server cybercrime danableed danabot information theft malware-as-a-service memory leak operation endgame smokeloader vulnerability
Related entities
2 observables, 1 intrusion sets (apt), 15 techniques (mitre), 2 malware, 4 others

Description

A critical named was discovered in 's , causing memory leaks from June 2022 to early 2025. This bug, introduced in version 2380, exposed sensitive information including threat actor details, server data, and victim credentials. The leak resulted from uninitialized memory in the C2 protocol update. Researchers gained insights into 's operations, infrastructure, and affiliates. In May 2025, law enforcement dismantled 's infrastructure and indicted 16 individuals in . The blog details the technical analysis of the , its impact, and the type of data exposed through the .

External references