ESET reported that the DanaBot banking Trojan broadened its operations from earlier campaigns in Australia and Poland to additional targets in Italy, Germany, Austria, and Ukraine. The largest activity remained focused on Poland, where attackers used invoice-themed spam emails to deliver the malware through the Brushaloader infection chain, combining PowerShell and VBS scripts to compromise victims.
Researchers said DanaBot’s operators also continued to enhance the malware’s modular capabilities, adding TOR-based C2 list updates, a new 64-bit stealer plug-in, and an RDP plug-in based on RDPWrap to strengthen remote access and reconnaissance. The malware was observed targeting banking portals, webmail services, cryptocurrency wallets, and corporate banking and remote access software, with the Ukrainian campaign showing particular interest in enterprise financial and remote administration tools.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
ESET reported continued development of DanaBot's modular capabilities, including TOR-based C2 list updates, a new 64-bit stealer plug-in, and an RDP plug-in based on RDPWrap for remote access and reconnaissance.
In September 2018, ESET reported that DanaBot had broadened its operations in Europe, including campaigns targeting Italy, Germany, Austria, and Ukraine.
After its initial Australia activity, DanaBot was observed targeting Poland, where ESET said the campaign became the largest and most active.
ESET said DanaBot was first observed targeting victims in Australia before later expanding to other regions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.