logo

DanaBot malware is back to infecting Windows after 6-month break

ID: 5cb4ceb6-557b-5b9e-8f8c-0519ca359a85

STIX ID: report--5cb4ceb6-557b-5b9e-8f8c-0519ca359a85

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-12

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

DanaBot has reappeared (version 669) six months after an international takedown, with a rebuilt C2 infrastructure leveraging Tor (.onion) and backconnect nodes; Zscaler researchers report new IoCs including cryptocurrency addresses. Historically a Delphi-based banking trojan that evolved into a modular infostealer and MaaS, DanaBot targets browser credentials and crypto wallets and has been used in large campaigns; organizations are advised to add the new IoCs to blocklists and update security tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.