DanaBot is a modular Windows malware family that emerged in 2018 as a banking trojan and evolved into a malware-as-a-service platform used for credential theft, information stealing, malware delivery, and follow-on intrusion activity. It has been associated with banking fraud, theft of credentials from browsers and other client applications, keylogging, web-injection activity, and remote-access functionality including VNC-based control. Later reporting shows it also being used to establish initial access for downstream operations, including ransomware deployment by affiliated actors.
DanaBot is operated through an affiliate model in which core operators maintain the malware and supporting infrastructure while customers or affiliates conduct campaigns. Its architecture has been described as multi-tiered and segmented, with substantial command-and-control infrastructure and victimization across dozens of countries. Researchers have assessed the operation as likely Russia-based, while specific affiliate activity has varied in targeting and objectives.
Observed delivery methods include spearphishing emails, malicious email attachments and links, HTML smuggling, and distribution through third-party loaders and malware distribution services such as Brushaloader and PrivateLoader. Campaigns have used scripts and archive-based infection chains to download and execute DanaBot on victim systems. DanaBot has also been observed in reply-chain spam and webmail abuse workflows, including harvesting email addresses from compromised mailboxes and sending further malicious messages from victim accounts.
Functionally, DanaBot supports persistence, process injection, credential theft, keylogging, exfiltration, and post-compromise malware delivery. Historical reporting also describes banking-focused web injections, collection of credentials from browsers, mail clients, FTP clients, VNC software, and Windows credential stores, plus selective anti-analysis and stealth features. Some variants or affiliated operations have used DanaBot to deliver secondary payloads for disruptive activity, including DDoS tooling, and to enable later-stage criminal operations.
Targeting has included financial institutions, government entities, enterprises, and users in multiple regions including Australia and Europe, with notable campaigns against Italian webmail users and Australian government targets. DanaBot has also appeared in broader crimeware ecosystems alongside other loaders, stealers, and banking trojans, and has been linked in reporting to cooperation or overlap with other criminal malware operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In late October CIRCL got notified about MS Exchange servers vulnerable for the recent critical Exchange RCE vulnerabilities CVE-2021-26427. Microsoft Exchange Server Remote Code Execution Vulnerability
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GandCrab aura également été propagé fin 2018 au cours de chaînes d’infection impliquant Dridex botnet ID 10202 et TA547, identifié par Proofpoint comme l’opérateur du cheval de Troie bancaire Danabot.
This threat actor typically targets Canada with false shipping lures, such as CanadaPost and DHL, and have attempted to deliver Ursnif, DanaBot, and Nymaim in the past.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Proofpoint first identified and named DanaBot in May 2018. Initially developed as a banking trojan, DanaBot was also used as an information stealer and loader for follow-on malware.
Following DanaBot's debut in May 2018, it quickly gained popularity due to its modular functionality supporting credit card theft, wire fraud, and exfiltration of cryptocurrency-related files.
39 distinct techniques documented for this family, organized by ATT&CK tactic.
Continue to look for attacks on weak credentials and suspicious login attempts... Protect cloud assets from communicating with bots that are attempting to perform password spraying attacks
Russian management infrastructure was observed connecting over RDP and VNC to what appeared to be the backup server... This activity originated from two ADMAN-AS, RU servers that appeared to serve as “jumpboxes” used for backend management.
the NPM repository account associated with a popular node.js was briefly hijacked and used to distribute a malicious script... This attack highlights the previously-exposed hazards associated with open-source repository poisoning.
Most of the malware distribution activity that we observe associated with Brushaloader leverages malicious email campaigns targeting specific geographic regions to distribute various malware payloads, primarily Danabot.
a great deal of fraud business logic is now implemented in JavaScript and sold to malware authors.
Executing the VBS file leads to downloading further malware using a PowerShell command.
Execution Regsvr32 – DanaBot file Rundll32 – DanaBot file Scripting – VBS file Service Execution – custom startup service User Execution – phishing link, unzipping archive, executing VBS file
Continue to look for attacks on weak credentials and suspicious login attempts... Protect cloud assets from communicating with bots that are attempting to perform password spraying attacks
The threat can also inject malware into other processes, such as winlogon.exe, explorer.exe, and svchost.exe... Defense Evasion ... Process Injection – explorer, winlogon, services, browser
Functionality on older systems include rootkit capabilities, including the ability to hide newly created services along with the directories the threat uses.
Defense Evasion ... Obfuscated Files or Information – data files, keylogging file
That code is a packer identical to that being used in recent Qbot malware attacks. The packer launches information-stealing malware
However, the referenced data in the href attribute is not downloaded from a URL but saved as a base64 string using the data URI scheme. This is also called HTML smuggling.
The threat can also inject malware into other processes, such as winlogon.exe, explorer.exe, and svchost.exe... Defense Evasion ... Process Injection – explorer, winlogon, services, browser
Continue to look for attacks on weak credentials and suspicious login attempts... Protect cloud assets from communicating with bots that are attempting to perform password spraying attacks
If both curl and wget failed to directly download the executable, the script then used Windows’ certificate utility (certutil.exe) to download a Base64-encoded version of the file and decode it as an executable.
Affiliates then distribute and use the malware as they see fit--mostly to steal credentials and commit banking fraud.
the JavaScript injected into the targeted webmail services’ pages can be broken down into two main features: DanaBot harvests email addresses from existing victims’ mailboxes. This is achieved by injecting a malicious script into each of the targeted webmail service’s webpages once a victim logs in, processing the victim’s emails and sending all email addresses it finds to a C&C server.
Protect cloud assets from communicating with bots that are attempting to perform password spraying attacks and begin blocking IoCs with Web Application Firewalls.
As can be seen in the screenshot above, the loader attempts to enumerate the following information about systems being infected: ProcessorId Windows operating system version Currently logged in Username Installed Antivirus Products System Make/Manufacturer Powershell version IP address information Available memory Current Working Directory System Installation Date/Time Display Adapter Information
it is quite likely that in addition to the DDoS attack, the actor is using DanaBot’s more typical functionality such as credential theft and document theft against any relevant victims as well.
Affiliates then distribute and use the malware as they see fit--mostly to steal credentials and commit banking fraud.
the JavaScript injected into the targeted webmail services’ pages can be broken down into two main features: DanaBot harvests email addresses from existing victims’ mailboxes. This is achieved by injecting a malicious script into each of the targeted webmail service’s webpages once a victim logs in, processing the victim’s emails and sending all email addresses it finds to a C&C server.
A layered communications infrastructure is used between a victim and the botnet controllers, where traffic is proxied through typically two or three tiers of C2s before it reaches the final tier, which consists of the panel that the threat actors operate from.
Command and Control Commonly Used Port – TCP port 443 Standard Application Layer Protocol – HTTPS
DanaBot has the functionality to transit victim data through Tor instead of using a direct connection between the victim and the C2, so the true bot population is likely larger than what we can see.
The VBS file is responsible for making an HTTP request to an attacker-controlled distribution server to download a malicious PE32 executable.
465 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
114 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular banking trojan that steals information, injects fake forms for payment theft, and can provide remote access via a VNC plugin.
DanaBot2
Referenced as related loader malware used to drop bundled payloads including Xworm in campaigns associated with Lumma delivery.
Financial malware active in Mexico and one of the leading malware families by victims and observed infections in 2025.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.