logo

DanaBot Launches DDoS Attack

ID: 17ff8979-90e2-5bc2-b7a2-248d1bedc71e

STIX ID: report--17ff8979-90e2-5bc2-b7a2-248d1bedc71e

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This ThreatLabz report documents an active DanaBot affiliate (ID 5) campaign that delivered a Delphi-based HTTP DDoS executable via DanaBot's download-and-execute functionality to target the Ukrainian Ministry of Defense webmail and an IP associated with invaders-rf.com; the report includes the DDoS binary SHA-256, screenshots, contextual analysis of DanaBot as a malware-as-a-service, and notes potential additional credential/document theft and uncertain attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.