logo

DanaBleed: DanaBot C2 Server Memory Leak Bug

ID: 61fcdff0-140c-5373-9fbd-24660bc4d189

STIX ID: report--61fcdff0-140c-5373-9fbd-24660bc4d189

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-06-09

Date Updated: 2026-05-01

...
...

**Executive summary:** This analysis describes the DanaBleed memory-leak vulnerability in DanaBot introduced in June 2022, where a C2 protocol change caused uninitialized padding in Delphi TMemoryStream to leak up to 1,792 bytes of C2 process memory per response—exposing backend C2 infrastructure, private keys, developer changelogs, debug paths, SQL statements, and large volumes of victim credentials and exfiltrated data over an extended period.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.