DanaBot, a malware-as-a-service platform used for credential theft, banking fraud, remote access, and data exfiltration, has remained active through both targeted intrusions and broad distribution campaigns. Researchers tied major software supply-chain compromises involving the ua-parser-js and coa NPM packages to DanaBot affiliate activity, where loaders and payloads were configured primarily for credential theft, while a separate affiliate used infected hosts to deliver a Delphi-based payload for HTTP DDoS attacks. Earlier reporting also documented a spearphishing campaign targeting personnel in an Australian government department, using a malicious VBS downloader and region-restricted delivery to install DanaBot from attacker-controlled infrastructure.

Pull IOCs and campaign context straight into your stack.
12 events from the most recent confirmed update back to the earliest known activity.
The NPM package COA was compromised in a second software supply chain attack that delivered DanaBot. Zscaler attributed this incident to the same DanaBot affiliate ID 40 seen in the UAParser.js compromise, again with credential-stealing functionality enabled.
The NPM package UAParser.js was compromised in a software supply chain attack and used to distribute both a cryptocurrency miner and DanaBot. Zscaler linked the DanaBot activity to affiliate ID 40, which enabled credential theft features but not banking webinjects.
DanaBot affiliate ID 4 configured infected systems to download and execute an additional Delphi-based executable that carried out a minimal HTTP DDoS attack against a Russian-language electronics forum.
FortiGuard discovered a targeted DanaBot attack against an individual in a Queensland state government department in Australia, followed within days by additional spearphishing against other members of the same organization. The campaign used a phishing email linking to a ZIP archive containing a malicious VBS downloader.
DanaBot was first discovered by Proofpoint as a malware-as-a-service platform used primarily for credential theft and banking fraud.
Malpedia published an autogenerated YARA rule, win_danabot_auto, for detecting the Windows malware family DanaBot. The rule metadata credits Felix Bilstein as author and indicates it was generated with yara-signator using sample-derived signatures.
Zscaler ThreatLabz released IDA Python scripts on GitHub to patch or simplify DanaBot obfuscation techniques such as junk byte jumps, dynamic returns, stack strings, and junk loops to aid reverse engineering.
Zscaler reported recently observing DanaBot version 2646 in the wild, underscoring that the malware remained active despite reduced prominence.
Lexfo reported that the hardcoded version number in newer DanaBot samples increased multiple times over a few weeks, indicating active ongoing development by the malware's operators.
Lexfo analyzed newer DanaBot samples that evolved beyond version 4 by adding a downloader component that retrieves and loads the main module, configuration, and plugins. The update introduced a two-stream communication model and additional functionality including an apparent unfinished InstallRDP capability.
Danabot version 3, marketed as DBot v.3, was released on the Russian-language cybercrime forum Exploit. Flashpoint assessed that the release emphasized new subscription tiers, lower pricing, setup guidance, and improved support rather than major technical changes.
The domain used to host the DanaBot payload in the Queensland-targeted campaign was recently registered, with FortiGuard noting the registration date and later observing a surge in activity from mostly Australian visitors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 61 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcezscaler.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceblog.lexfo.fr
Open sourceflashpoint.io
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.