DanaBot is a modular Windows banking trojan and malware-as-a-service platform first observed in 2018. Initially associated with theft of banking credentials and fraud, it later evolved into a broader crimeware platform used for credential theft, keylogging, information stealing, remote access through VNC-related functionality, payload delivery, and establishment of initial access for follow-on operations including ransomware. It has also been observed delivering secondary malware and enabling downstream intrusion activity, making it both an infostealer and an access-enablement platform.
DanaBot is operated through an affiliate model in which core operators maintain the malware, management panels, and shared command-and-control infrastructure while affiliates conduct campaigns. Reporting has linked its operations and management infrastructure to Russia, and the malware has been used in activity affecting victims across dozens of countries. Victimology has included financial targets, government entities, universities, law firms, and users of online banking and email services. Countries repeatedly noted among impacted populations include the United States, Mexico, Brazil, Australia, and multiple European states.
Capabilities attributed to DanaBot include credential theft from browsers and other applications, keylogging, banking web injection, download-and-execute of additional payloads, process injection, persistence through service creation, and anti-analysis or stealth features. Some variants and campaigns have shown rootkit-style hiding behavior on older Windows systems. Operators and affiliates have used DanaBot to deploy additional malware families and, in some cases, to support follow-on ransomware activity. Separate reporting also documented use of DanaBot’s delivery mechanism to launch a second-stage HTTP flood tool in a DDoS operation during the 2022 war in Ukraine.
Observed delivery methods include spearphishing emails, malicious email attachments or links, HTML smuggling, and distribution through other malware loaders such as Brushaloader and PrivateLoader. DanaBot has also appeared in malicious software-crack ecosystems and trojanized software delivery chains. Campaigns have included geographically selective delivery, such as restricting payload access to Australian victims in one targeted operation against a Queensland government department.
DanaBot remains notable for combining classic banking-trojan tradecraft with flexible post-compromise utility. Its evolution from a banking-focused trojan into a multi-purpose criminal platform has made it relevant to both fraud investigations and broader intrusion-response efforts, especially where credential theft, malware staging, and ransomware precursor activity intersect.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In late October CIRCL got notified about MS Exchange servers vulnerable for the recent critical Exchange RCE vulnerabilities CVE-2021-26427. Microsoft Exchange Server Remote Code Execution Vulnerability
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GandCrab aura également été propagé fin 2018 au cours de chaînes d’infection impliquant Dridex botnet ID 10202 et TA547, identifié par Proofpoint comme l’opérateur du cheval de Troie bancaire Danabot.
This threat actor typically targets Canada with false shipping lures, such as CanadaPost and DHL, and have attempted to deliver Ursnif, DanaBot, and Nymaim in the past.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Following DanaBot's debut in May 2018, it quickly gained popularity due to its modular functionality supporting credit card theft, wire fraud, and exfiltration of cryptocurrency-related files.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Continue to look for attacks on weak credentials and suspicious login attempts... Protect cloud assets from communicating with bots that are attempting to perform password spraying attacks
On November 4th, 2021, threat actors hijacked the NPM library COA, and uploaded malicious versions of the library for victims to download.
This is the third NPM Library related supply chain attack to occur since October 22nd. All three attacks have shared TTPs and are believed to have been conducted by the same threat actor. The first two attacks against the UA-Parser-JS NPM library and the COA NPM Library were confirmed to have stemmed from compromised developer accounts.
Most of the malware distribution activity that we observe associated with Brushaloader leverages malicious email campaigns targeting specific geographic regions to distribute various malware payloads, primarily Danabot.
DanaBot is an info-stealer malware... capable of... downloading and executing additional malicious content.
Execution Regsvr32 – DanaBot file Rundll32 – DanaBot file Scripting – VBS file Service Execution – custom startup service User Execution – phishing link, unzipping archive, executing VBS file
The threat can also inject malware into other processes, such as winlogon.exe, explorer.exe, and svchost.exe... Defense Evasion ... Process Injection – explorer, winlogon, services, browser
Functionality on older systems include rootkit capabilities, including the ability to hide newly created services along with the directories the threat uses.
Defense Evasion ... Obfuscated Files or Information – data files, keylogging file
That code is a packer identical to that being used in recent Qbot malware attacks. The packer launches information-stealing malware
The threat can also inject malware into other processes, such as winlogon.exe, explorer.exe, and svchost.exe... Defense Evasion ... Process Injection – explorer, winlogon, services, browser
Continue to look for attacks on weak credentials and suspicious login attempts... Protect cloud assets from communicating with bots that are attempting to perform password spraying attacks
If both curl and wget failed to directly download the executable, the script then used Windows’ certificate utility (certutil.exe) to download a Base64-encoded version of the file and decode it as an executable.
Affiliates then distribute and use the malware as they see fit--mostly to steal credentials and commit banking fraud.
Protect cloud assets from communicating with bots that are attempting to perform password spraying attacks and begin blocking IoCs with Web Application Firewalls.
the malware targets VNC and FTP clients, mail clients, web browsers and a host of other Internet-connected applications for credential theft, as well as Windows’ own credential manager.
As can be seen in the screenshot above, the loader attempts to enumerate the following information about systems being infected: ProcessorId Windows operating system version Currently logged in Username Installed Antivirus Products System Make/Manufacturer Powershell version IP address information Available memory Current Working Directory System Installation Date/Time Display Adapter Information
it is quite likely that in addition to the DDoS attack, the actor is using DanaBot’s more typical functionality such as credential theft and document theft against any relevant victims as well.
Command and Control Commonly Used Port – TCP port 443 Standard Application Layer Protocol – HTTPS
The malicious COA versions appear to deliver the DanaBot malware; a trojan capable of stealing sensitive information such as credentials, as well as downloading and executing additional malicious content.
465 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
119 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prominent malware family reported as active in Mexico.
Modular banking trojan that steals information, injects fake forms for payment theft, and can provide remote access via a VNC plugin.
DanaBot2
Referenced as related loader malware used to drop bundled payloads including Xworm in campaigns associated with Lumma delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.