DanaBot

Aliases: DanaTools

Malware type
trojan, credential-stealer
Family
Malware family
Last IoC activity
2026-07-22 04:04:50
Profile updated
2026-07-07 12:41:57

Targeted industries: financial-services

Targeted regions: country_code:us country_code:au country_code:nz country_code:pl

Context

Proofpoints describes DanaBot as the latest example of malware focused on persistence and stealing useful information that can later be monetized rather than demanding an immediate ransom from victims. The social engineering in the low-volume DanaBot campaigns we have observed so far has been well-crafted, again pointing to a renewed focus on “quality over quantity” in email-based threats. DanaBot’s modular nature enables it to download additional components, increasing the flexibility and robust stealing and remote monitoring capabilities of this banker.

Detection coverage

  • 2 YARA rules

Detection rules

  • RUSSIANPANDA_Danabot (yara-rule)
  • MALPEDIA_Win_Danabot_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • x.com — 1730383711437283757 (report)
  • CrowdStrike — Report2021Gtr (report)
  • CISA — Aa22 110A (report)
  • twitter.com — 1730383711437283757 (report)
  • cloud.google.com — Detecting Disrupting Malvertising Backdoors (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • ESET — Eset Threat Report Q22020 (report)
  • assets.virustotal.com — 2021Trends (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
  • spamhaus.org — 2020 Q2 Spamhaus Botnet Threat Report (report)
  • marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
  • blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
  • lastline.com — Evolution Of Excel 4 0 Macro Weaponization (report)
  • proofpoint.com — Security Brief Clickfix Social Engineering Technique Floods Threat Landscape (report)
  • resources.malwarebytes.com — Ctnt Q1 2020 Covid Report Final (report)
  • f5.com — Banking Trojans A Reference Guide To The Malware Family Tree (report)
  • Kaspersky — 101638 (report)
  • enterprise.verizon.com — 2019 Data Breach Investigations Report (report)
  • Kaspersky — 107498 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Danabot (report)
  • blog.lexfo.fr — Danabot Malware (report)
  • proofpoint.com — Danabot New Banking Trojan Surfaces Down Under 0 (report)

External references