logo

Operation Endgame 2.0: DanaBusted

ID: 6de68dbc-2c25-5982-97fa-4e6b79aefa3f

STIX ID: report--6de68dbc-2c25-5982-97fa-4e6b79aefa3f

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-05-22

Date Updated: 2026-05-01

...
...

This report provides a technical analysis of DanaBot, a Malware-as-a-Service banking and info-stealing trojan with a loader and main module, modular capability set (keylogger, form/file/browser stealer, SOCKS proxy, remote desktop, web injects, screenshot/video capture, and second-stage payload delivery), custom encrypted TCP protocol, multiple persistence mechanisms, active development (many builds through 2025), and distribution via affiliates—used to deploy additional malware including RATs and ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.