logo

ThreatLabz

ID: f7bb68be-fab4-5dbc-91ef-21b273f02c9d

STIX ID: report--f7bb68be-fab4-5dbc-91ef-21b273f02c9d

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-06-04

Date Updated: 2026-05-01

...
...

This report analyzes DanaBot, a malware-as-a-service info-stealer first seen in 2018 that steals credentials, session cookies, and account information for banking fraud, cryptocurrency theft, and espionage. It documents numerous obfuscation techniques (junk byte jumps, dynamic returns, stack strings, junk loops/strings) and presents a suite of IDA Python scripts to deobfuscate binaries, with a provided SHA256 IOC for a DanaBot sample.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.