DanBot

MITRE ATT&CK: S1014 View on attack.mitre.org

Aliases: DanBot

First seen
2018-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Last IoC activity
2026-07-21 16:04:13
Profile updated
2026-07-07 12:56:41

Targeted industries: energy-and-utilities technology-and-telecommunications

Context

DanBot is a first-stage remote access Trojan written in C# that has been used by HEXANE since at least 2018.

Detection coverage

  • 1 YARA rules
  • 292 Sigma rules

Malware & tools used

  • Scheduled Task (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • VNC (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • File Deletion (attack-pattern)
  • Malicious File (attack-pattern)
  • DNS (attack-pattern)
  • Data from Local System (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Web Protocols (attack-pattern)
  • Visual Basic (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Danbot_Auto (yara-rule)

Reports & references

  • secureworks.com — Lyceum Takes Center Stage In Middle East Campaign (report)
  • secureworks.com — Cobalt Lyceum (report)
  • vblocalhost.com — Vb2021 Kayal Etal (report)
  • youtube.com — Watch (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Danbot (report)
  • cyberx-labs.com — Deep Dive Into The Lyceum Danbot Malware (report)
  • clearskysec.com — Siamesekitten (report)
  • otx.alienvault.com — 5D4301Edb3F3406Ac01Acc0F (report)
  • dragos.com — Dragos Oil And Gas Threat Perspective 2019 (report)
  • MITRE ATT&CK — S1014 (report)

External references