DanaBot Trojan Returns To Banking Threat Landscape
ID: ee013d16-7c2a-55e0-a42d-ae66446cd6a4
STIX ID: report--ee013d16-7c2a-55e0-a42d-ae66446cd6a4
Feed Name: Cyble Blog
This Cyble report analyzes a newly resurfaced variant of the DanaBot banking trojan, detailing its UPX-packed Delphi loader, DLL export-based runtime behavior, anti-analysis techniques, TOR-capable C2 infrastructure, AES/RSA-based C2 protocol, and modular capabilities (credential theft, browser injection, keylogging, potential ransomware). The report provides multiple IOCs (hashes, IP addresses, and an .onion host), runtime analysis artifacts, and actionable recommendations for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
