DanaBot is a modular banking Trojan and stealer written in Delphi, first publicly reported by Proofpoint in May 2018 after malicious email campaigns targeting users in Australia. It has operated as a malware-as-a-service platform used by multiple affiliates and was later linked by U.S. authorities to a Russia-based cybercrime organization. DanaBot has been distributed through spam emails with malicious attachments or hyperlinks, macro-enabled Word documents, zipped JavaScript downloaders, Brushaloader/BrushaLoader using PowerShell and VBS scripts, Hancitor-delivered chains, software cracks and warez sites, MSI loaders, and ClickFix-style campaigns on compromised or attacker-controlled websites. Reported delivery chains also include bundled deployment with other malware such as Pony variants, Xworm, SectopRAT/ArechClient, and a likely cryptocurrency miner.
DanaBot uses a multi-stage, multi-component architecture consisting of a loader, a main module, and plug-ins or modules. Across reporting, observed capabilities include banking webinjects and session hijacking, credential theft from browsers, FTP, VPN, chat, email, and other applications, theft of cookies, browsing history, device and system information, screenshots, file listings, cryptocurrency wallet information, keylogging, video recording of user activity, full remote access, VNC, SOCKS/proxy and sniffer functionality, TOR-based communications or C2 list updates, and an RDP plug-in based on RDPWrap. Proofpoint and ESET documented continued development, including a new encrypted C2 protocol introduced in late January 2019 using AES and RSA, changes to loader architecture, campaign IDs, 64-bit stealer support, and additional remote-access functionality.
Targeting documented in the content includes Australia, Poland, Italy, Germany, Austria, Ukraine, the United States, Canada, the United Kingdom, Mexico, and broader Europe and North America. Campaigns targeted banking portals, webmail services, cryptocurrency-related files and processes, and in Ukraine also corporate banking software and remote access tools. Reporting also notes DanaBot activity and victim prevalence in Mexico in 2025. U.S. authorities stated that one DanaBot variant was used for fraud and credential theft, while a second variant targeted military, diplomatic, government, law enforcement, and related entities in North America and Europe, recording victim interactions and sending stolen data to separate servers.
The malware has been associated with multiple threat actors and ecosystems. Proofpoint initially attributed early Australian distribution to TA547 and later assessed DanaBot was used by multiple affiliates. BrushaLoader was strongly linked to DanaBot affiliate ID 3, and other reporting described DanaBot as used by multiple carding gangs rather than a single actor. Law enforcement actions under Operation Endgame disrupted DanaBot infrastructure, and by May 2025 the DanaBot network was reported dismantled with charges against 16 people. The U.S. Department of Justice stated DanaBot infected more than 300,000 computers worldwide and caused at least $50 million in damage.
High-confidence indicators mentioned in the content include C2 or related infrastructure such as 84.54.37[.]102, 89.144.25[.]243, 89.144.25[.]104, 178.209.51[.]211, 185.92.222[.]238, 192.71.249[.]51, 149.154.152.64, 149.154.157.220, 158.255.215.31, 178.209.51.227, 37.235.53.232, 45.77.231.138, 45.77.51.69, 45.77.54.180, 45.77.96.198, 95.179.151.252, 23.226.132.92, 23.106.123.249, 108.62.141.152, 104.144.64.163, and TOR hostnames y7zmcwurl6nphcve.onion and 5jjsgjephjcua63go2o5donzw5x4hiwn6wh2dennmyq65pbhk6qflzyd.onion. Additional URLs and domains tied to delivery or related activity include hxxp://bbc[.]lumpens[.]org/tXBDQjBLvs.php, hxxp://members[.]giftera[.]org/whuBcaJpqg.php, hxxp://45.147.230.58/palata.exe, eressedn27.top, morttttq12.top, and attacker-controlled lure domains such as antigravity[.]study. Sample hashes explicitly mentioned include c0eb802f394e758da4feb0d6c3b817bf1f64880ab9bc851937d5ef774161585d and 8327931a5d2430526862d789b9654c9c8da7bc64519d210a93e4720aac7ccaa0.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint researchers discovered a new banking Trojan, dubbed “DanaBot”, targeting users in Australia via emails containing malicious URLs.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Following DanaBot's debut in May 2018, it quickly gained popularity due to its modular functionality supporting credit card theft, wire fraud, and exfiltration of cryptocurrency-related files.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
After being discovered in May 2018 as part of Australia-targeted spam campaigns... appearing in malspam campaigns in Poland, Italy, Germany, Austria and Ukraine, as well as in the United States... At the time of writing, the new version is being distributed under two scenarios: As “updates” delivered to existing DanaBot victims Via malspam in Poland
DanaBot includes a significant amount of junk code... DanaBot uses Windows API function hashing and encrypted strings to prevent analysts and automated tools from easily determining the code’s purpose.
Configure various aspects of the malware (e.g., video recording of the screen, keylogging, and webinjects) (Figure 4)
Sniffer plug-in – injects malicious scripts into a victim’s browser, usually while visiting internet banking sites
0x130 - Upload collected information to C&C server (e.g., screenshot of a victim’s computer; system information) ... 0x132 - Ask C&C server for further commands; there are around 30 available commands typical of backdoors, including launching plugins, gathering detailed system information
Configure various aspects of the malware (e.g., video recording of the screen, keylogging, and webinjects) (Figure 4)
Sniffer plug-in – injects malicious scripts into a victim’s browser, usually while visiting internet banking sites
0x130 - Upload collected information to C&C server (e.g., screenshot of a victim’s computer; system information)
Configure various aspects of the malware (e.g., video recording of the screen, keylogging, and webinjects) (Figure 4)
The fast-evolving, modular Trojan DanaBot has undergone further changes, with the latest version featuring an entirely new communication protocol... The protocol, introduced to DanaBot at the end of January 2019, adds several layers of encryption to DanaBot’s C&C communication.
Table 1: List of modules typically seen... FF1 Sniffer Proxy ... FF5 TOR TOR proxy
TOR plug-in – installs a TOR proxy and enables access to .onion web sites
According to our analysis, the loader component uses the following commands: 0x12D - Download 32/64-bit launcher component 0x12E - Request list of plugins and configuration files 0x12F - Download plugin/configuration files
VNC plug-in – establishes a connection to a victim’s computer and remotely controls it
In August 2018, the attackers started using the TOR plug-in for updating the C&C server list from y7zmcwurl6nphcve.onion.
Following the latest changes, DanaBot uses the AES and RSA encryption algorithms in its C&C communication. The new communication protocol is complicated, with several encryption layers being used... without access to the corresponding RSA keys, it is impossible to decode sent or received packets.
137 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
76 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DanaBot2
Referenced as related loader malware used to drop bundled payloads including Xworm in campaigns associated with Lumma delivery.
Financial malware active in Mexico and one of the leading malware families by victims and observed infections in 2025.
The disruption is the latest phase of Operation Endgame, which previously disrupted other malware families, such as DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.