Danabot: Analyzing a fallen empire
ID: ccd3390f-c48c-5125-9255-0cb4dc50d0f7
STIX ID: report--ccd3390f-c48c-5125-9255-0cb4dc50d0f7
Feed Name: WeLiveSecurity (ESET Research)
ESET Research provides a technical analysis of Danabot, a Delphi-based infostealer offered as malware-as-a-service since 2018; the report details its capabilities (credential/browser stealing, keylogging, screen/video capture, remote access, FileGrabber, webinjects), infrastructure (C&C server, admin panel, backconnect, proxy chain, Tor fallback), distribution methods (email spam, loaders, malvertising and deceptive sites), build types and configuration options, encryption/communication mechanisms (AES-256 + RSA, custom TCP), observed payloads (including ransomware such as LockBit), IoCs (file hashes, IPs, domains), and MITRE ATT&CK mapping, and notes a coordinated law-enforcement disruption of the Danabot infrastructure and attribution of developer/operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
