Danabot Takedown Deals Blow to Russian Cybercrime
ID: e4fa9067-01ae-5ec2-b4fc-db986962ca4b
STIX ID: report--e4fa9067-01ae-5ec2-b4fc-db986962ca4b
Feed Name: Dark Reading
Date Published: 2025-05-27
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
**Executive summary:** The report covers a coordinated international takedown of the Danabot malware-as-a-service and botnet—originally an infostealer/banking trojan that evolved into a large MaaS operation used to distribute ransomware and conduct espionage; US authorities seized C2 servers and 16 individuals were indicted, though key leaders remain at large in Russia, and private-sector partners played a major role in the disruption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
