DanaBot Activity
ID: 2b73a6c6-529e-532d-9e3e-452f13beec9e
STIX ID: report--2b73a6c6-529e-532d-9e3e-452f13beec9e
Feed Name: Zscaler Security Research Blog
## Executive Summary This report describes active DanaBot campaigns in late 2021 where threat actors (affiliate ID 40) conducted two large software supply-chain compromises of popular NPM packages (UAParser.js on 2021-10-22 and COA on 2021-11-04) to distribute DanaBot loaders and main components, and affiliate ID 4 deployed a Delphi-based DDoS payload against a Russian electronics forum; the document includes IoCs (download URLs, SHA-256 hashes, C2 IPs and .onion addresses), malware configuration details, and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
