Proofpoint reported that DanaBot, a Delphi-based banking Trojan and stealer sold through a malware-as-a-service model, re-emerged with a fourth major version after activity dropped in mid-2020. The updated malware kept its modular design, hardcoded command-and-control infrastructure, TOR fallback, and a binary TCP protocol protected with AES-256 and RSA, while continuing to support multiple affiliates. Researchers said recent infections were tied to software cracks and warez sites delivering a multi-stage bundle that included a credential stealer, a likely AutoIT cryptocurrency miner, and DanaBot; the stealer collected browser credentials, cookies, screenshots, system details, and potentially cryptocurrency wallet data.
Earlier Proofpoint research showed DanaBot had already expanded from Australia into Europe and the United States through large affiliate-driven campaigns, including eFax-themed phishing that used malicious macro documents to install Hancitor, then fetch Pony stealer variants and DanaBot. Proofpoint also uncovered what it assessed to be the malware’s affiliate control panel, a graphical client tied to DanaBot through shared infrastructure, protocol overlap, and an embedded RSA public key, indicating a centralized global backend rather than fully separate affiliate infrastructure. The panel exposed extensive operator capabilities, including keylogging, webinjects, screen recording, file operations, screenshots, command execution, and remote access through VNC and RDP.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Proofpoint reported that DanaBot activity had sharply declined following June 2020. This lull preceded the later emergence of a new major version.
Proofpoint observed at least one current DanaBot distribution method tied to software cracks and warez websites. These sites delivered a multi-stage malware bundle including a stealer, a likely AutoIT cryptocurrency miner, and DanaBot.
Proofpoint identified a fourth major version of DanaBot after the post-June 2020 decline in activity. The updated malware retained a modular architecture and malware-as-a-service affiliate model, with hardcoded C2 infrastructure, TOR fallback, and an AES-256/RSA-protected binary TCP C2 protocol.
Proofpoint linked an exposed affiliate client to DanaBot samples observed after the February 2019 protocol update. The shared RSA key and protocol overlap helped connect the control panel to the malware operation.
Proofpoint analyzed a graphical client it assessed to be the DanaBot affiliate control panel, showing capabilities to build malware, review stolen data, and remotely operate infected machines. The research supported the view that DanaBot used a centralized global C2 backend shared by multiple affiliates.
On September 26, a campaign targeting U.S. recipients used malicious eFax-themed emails to deliver macro documents that installed Hancitor, which then fetched Pony stealer variants and DanaBot. Proofpoint cited this campaign as part of DanaBot's expansion into the United States.
Proofpoint described DanaBot as a Delphi-based banking Trojan first identified in May 2018. This marked the earliest explicit appearance of the malware family in the provided references.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 89 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
proofpoint.com
Open sourceproofpoint.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.