DanaBot, a well-known banking trojan and information stealer, has re-emerged with a new Windows variant (version 669) after a six-month hiatus following the law enforcement takedown known as Operation Endgame. Security researchers from Zscaler ThreatLabz and others have observed that the new version leverages both standard IP-based command-and-control (C2) domains and Tor (.onion) addresses, as well as "backconnect" nodes, to manage infections and deliver additional payloads. The updated malware exhibits increased modularity, allowing for remote payload management, infection parameter updates, and enhanced persistence, making it more difficult to detect and remove. Attackers are distributing DanaBot primarily through spear-phishing emails, malicious attachments, SEO poisoning, and malvertising campaigns, with the malware capable of harvesting credentials, cryptocurrency wallet data, and facilitating lateral movement within compromised networks.
The resurgence of DanaBot highlights the resilience of cybercriminal operations, as the core operators were not apprehended during the takedown, enabling them to rebuild infrastructure and resume activity. Researchers have identified new cryptocurrency wallet addresses used by the threat actors to receive stolen funds in BTC, ETH, LTC, and TRX. The malware continues to be offered as a malware-as-a-service (MaaS), rented out to other cybercriminals for use in various campaigns, including those that may lead to ransomware deployment. Organizations are advised to update their blocklists with the latest indicators of compromise (IoCs) and remain vigilant against evolving social engineering tactics used to deliver DanaBot.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Alongside its findings on the revived DanaBot activity, Zscaler shared indicators of compromise associated with the latest campaign. The published technical details included infrastructure and other artifacts intended to help defenders detect the malware's return.
By November 2025, Zscaler ThreatLabz reported that DanaBot had resurfaced in the threat landscape with a new Windows variant, version 669, after the post-Endgame lull. The researchers said the renewed campaign used newly identified command-and-control infrastructure and cryptocurrency wallet addresses linked to the operators.
In May 2025, the international law-enforcement Operation Endgame targeted initial-access malware operations, disrupting DanaBot activity along with multiple other malware families and resulting in arrest warrants. DanaBot activity then dropped for roughly six months following the action.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.