#DanaBot
Some good news! DanaBot takedown and charges revealed today! This is a massive win for defenders and the community. www.justice.gov/usao-cdca/pr...

Proofpoint also published a brief history of DanaBot today, including examples of the espionage overlap. www.proofpoint.com/us/blog/thre...
16 Defendants Federally Charged in Connection with DanaBot Malware Scheme That Infected Computers Worldwide
A federal grand jury indictment and criminal complaint unsealed today charge 16 defendants who allegedly developed and deployed the DanaBot malware which a Russia-based cybercrime organization control...
www.justice.gov
May 22, 2025 at 8:14 PM
The #FBI and #DCIS disrupted #Danabot. #ESET was one of several companies that cooperated in this effort. www.welivesecurity.com/en/eset-rese... 1/6
www.welivesecurity.com
May 22, 2025 at 8:06 PM
I successfully completed DanaBot Blue Team Lab at @CyberDefenders!
cyberdefenders.org/b...

#CyberDefenders #CyberSecurity #BlueYard #BlueTeam #InfoSec #SOC #SOCAnalyst #DFIR
CyberDefenders | DanaBot blue team lab
wearyandroid successfully completed DanaBot lab.
cyberdefenders.org
March 20, 2025 at 8:02 AM
In May 2025, #ESET participated in operations that largely disrupted the infrastructure of two notorious infostealers: #LummaStealer and #Danabot. 1/6
July 11, 2025 at 12:27 PM
NEW: The US has charged 16 Russian nationals for allegedly creating and distributing the DanaBot malware, which has allegedly infected at least 300k machines worldwide and has been used for ransomware, DDoS attacks, and espionage. @agreenberg.bsky.social reports: www.wired.com/story/us-cha...
Feds Charge 16 Russians Allegedly Tied to Botnets Used in Ransomware, Cyberattacks, and Spying
A new US indictment against a group of Russian nationals offers a clear example of how, authorities say, a single malware operation can enable both criminal and state-sponsored hacking.
www.wired.com
May 22, 2025 at 7:59 PM
Today, Proofpoint joins the cybersecurity community and the U.S. and international law enforcement in celebrating the disruption of #DanaBot, a malware-as-a-service used by sophisticated cybercriminals since 2018. brnw.ch/21wSRiZ
A Brief History of DanaBot, Longtime Ecrime Juggernaut Disrupted by Operation Endgame | Proofpoint US
Key Findings: Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on
brnw.ch
May 22, 2025 at 7:48 PM
The US DOJ charges 16 individuals allegedly linked to a Russia-based malware operation known as DanaBot that infected 300,000+ machines globally (Andy Greenberg/Wired)

Main Link | Techmeme Permalink
May 22, 2025 at 8:30 PM
-DanaBot and Lumma Stealer taken down
-ODNI wants a centralized data broker platform
-Chinese IMSI catcher spy ring broken up in Turkiye
-APT28 hacked border cameras to track Ukrainian military aid
-Cetus hacked for $223m

Podcast: risky.biz/RBNEWS428/
Newsletter: news.risky.biz/risky-bullet...
May 23, 2025 at 7:42 AM
A vulnerability in the DanaBot malware operation introduced in June 2022 update led to the identification, indictment, and dismantling of their operations in a recent law enforcement action.
DanaBot malware operators exposed via C2 bug added in 2022
A vulnerability in the DanaBot malware operation introduced in June 2022 update led to the identification, indictment, and dismantling of their operations in a recent law enforcement action.
www.bleepingcomputer.com
June 10, 2025 at 9:45 PM
Hackers Weaponize Word Files To Deliver DanaBot Malware
Hackers Weaponize Word Files To Deliver DanaBot Malware
Recent email campaigns distribute DanaBot malware through two document types: those using equation editor exploits and those containing
cybersecuritynews.com
May 14, 2024 at 10:29 AM
The successful break-up of DanaBot marks the second high-profile law enforcement disruption of a widespread malware operation in as many days. via @mattkapko.com cyberscoop.com/danabot-malw...
DanaBot malware operation seized in global takedown
The successful break-up of DanaBot marks the second high-profile law enforcement disruption of a widespread malware operation in as many days.
cyberscoop.com
May 22, 2025 at 10:56 PM
Ok.... the timer seems to be for Europol related stuff

DOJ just announced charges against 16 DanaBot members:
www.justice.gov/usao-cdca/pr...
16 Defendants Federally Charged in Connection with DanaBot Malware Scheme That Infected Computers Worldwide
A federal grand jury indictment and criminal complaint unsealed today charge 16 defendants who allegedly developed and deployed the DanaBot malware which a Russia-based cybercrime organization control...
www.justice.gov
May 22, 2025 at 8:46 PM
DanaBot had a HeartBleed-like bug for three years

Leaked all the juicy stuff, such as threat actor usernames, IP addresses, private keys, and loads more

www.zscaler.com/blogs/securi...
DanaBleed: DanaBot C2 Server Memory Leak Bug | ThreatLabz
A flaw in DanaBot's C2 server code caused a memory leak that we named "DanaBleed", exposing sensitive data and offering researchers a look into DanaBot’s operations.
www.zscaler.com
June 10, 2025 at 11:40 AM
Great writeup on DanaBot infrastructure from Team Cymru! www.team-cymru.com/post/inside-...
Inside DanaBot’s Infrastructure: In Support of Operation Endgame II | Team Cymru
This blog explores DanaBot a
www.team-cymru.com
May 22, 2025 at 8:42 PM
Looks like there's a DanaBot botnet takedown happening tomorrow

😂
May 22, 2025 at 8:41 PM
⚠️ DanaBot malware returns after six-month hiatus

The banking Trojan DanaBot has resumed Windows attacks targeting financial institutions and using Microsoft Outlook and malicious ad campaigns to distribute payloads.

👉🏻 block macros, update Outlook filters and enable multi-factor authentication.
November 13, 2025 at 10:37 AM
LumaStealer and DanaBot operators:
two men are standing next to each other and one is saying what is dead may never die
ALT: two men are standing next to each other and one is saying what is dead may never die
media.tenor.com
May 22, 2025 at 9:36 PM
Feds have seized infrastructure and charged 16 members of a hacker group based in Russia that allegedly sold access to the DanaBot malware, used in everything from cybercrime like bank fraud and ransomware to espionage and DDOS attacks against Ukraine. www.wired.com/story/us-cha...
Feds Charge 16 Russians Allegedly Tied to Botnets Used in Ransomware, Cyberattacks, and Spying
A new US indictment against a group of Russian nationals offers a clear example of how, authorities say, a single malware operation can enable both criminal and state-sponsored hacking.
www.wired.com
May 22, 2025 at 7:59 PM
Glad to see Radio Free Europe/Radio Liberty journalists are still plying their trade, which is operating on emergency funds from the EU after Trump killed its budget.

The Hidden Threat: How DanaBot Malware Facilitated Data Theft and Russian State-Sponsored Spying
www.rferl.org/a/russia-dan...
The Hidden Threat: How DanaBot Malware Facilitated Data Theft and Russian State-Sponsored Spying
The Russian-made DanaBot virus was reportedly used not only for crimes such as stealing credit card information, bank account numbers, and cryptocurrency wallets -- but also for espionage by Russian i...
www.rferl.org
June 20, 2025 at 10:20 AM
New Danabot Windows version appears in the threat landscape after May disruption
New Danabot Windows version appears in the threat landscape after May disruption
DanaBot returns after 6 months with a new Windows variant (v669), marking its comeback after being disrupted by Operation Endgame in May.
securityaffairs.com
November 12, 2025 at 7:42 PM
DanaBot malware operation seized in global takedown
DanaBot malware operation seized in global takedown
The successful break-up of DanaBot marks the second high-profile law enforcement disruption of a widespread malware operation in as many days.
cyberscoop.com
May 22, 2025 at 11:04 PM