DanaBot is a Russia-based malware-as-a-service cybercrime operation centered on the DanaBot banking trojan and related botnet infrastructure. Active since at least 2018, the operation is structured around core operators who develop and maintain the malware, command-and-control panels, and shared infrastructure, while affiliates conduct intrusions and fraud campaigns under an affiliate-ID model. The group is widely associated with credential theft, banking fraud, and broader financially motivated intrusion activity, and the malware has also been used as a precursor to ransomware operations. DanaBot is primarily known for stealing credentials and other victim data, including information useful for financial fraud and follow-on compromise. Its operators and affiliates have used the platform to deliver additional payloads through download-and-execute functionality, enabling post-compromise flexibility and supporting downstream criminal activity. Reporting also indicates expansion into cryptocurrency theft capabilities. Although principally a financially motivated criminal service, DanaBot infrastructure and affiliates have also been linked to disruptive activity. In March 2022, a DanaBot affiliate used the platform to deploy a second-stage tool dedicated to HTTP-based distributed denial-of-service activity against Ukrainian targets during the opening phase of Russia’s invasion of Ukraine. That incident demonstrated that the ecosystem could support operations beyond conventional banking-trojan use cases, though the precise sponsorship or direction of that specific activity remains unclear. DanaBot has been tracked by Microsoft as Storm-1044 in its financially motivated actor taxonomy. The operation has also been a significant target of multinational law-enforcement disruption, including Operation Endgame. U.S. prosecutors have indicted 16 members of the Russia-based DanaBot operators, reinforcing the assessment that the operation is rooted in Russia. Known aliases and related labels include DanaBot, DanaBot affiliates, DanaBot operators, and Microsoft’s Storm-1044 designation for the financially motivated cluster associated with the malware ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DanaBot affiliate, identified as affiliate ID 5, used DanaBot’s download-and-execute capability to deliver a second-stage Delphi-based DDoS payload targeting the Ukrainian Ministry of Defense webmail server and later a hardcoded IP associated with invaders-rf[.]com. The content notes DanaBot affiliates typically use the platform for credential theft and banking fraud.
DanaBot operators are a Russia-based cybercriminal group responsible for operating the DanaBot malware, which has been targeted by law enforcement for takedown and prosecution.
DanaBot operators are a Russia-based cybercriminal group responsible for operating the DanaBot malware, which has been targeted by law enforcement for takedown and prosecution.
DanaBot is a banking trojan that has resurfaced with new infrastructure and capabilities, targeting cryptocurrency wallets and using Tor and BackConnect nodes for C2.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.