logo

Danabot: Analyzing a fallen empire

ID: ccd3390f-c48c-5125-9255-0cb4dc50d0f7

STIX ID: report--ccd3390f-c48c-5125-9255-0cb4dc50d0f7

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
78/100

Date Published: 2025-05-22

Date Updated: 2026-05-01

...
...

ESET Research provides a technical analysis of Danabot, a Delphi-based infostealer offered as malware-as-a-service since 2018; the report details its capabilities (credential/browser stealing, keylogging, screen/video capture, remote access, FileGrabber, webinjects), infrastructure (C&C server, admin panel, backconnect, proxy chain, Tor fallback), distribution methods (email spam, loaders, malvertising and deceptive sites), build types and configuration options, encryption/communication mechanisms (AES-256 + RSA, custom TCP), observed payloads (including ransomware such as LockBit), IoCs (file hashes, IPs, domains), and MITRE ATT&CK mapping, and notes a coordinated law-enforcement disruption of the Danabot infrastructure and attribution of developer/operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.