logo

DanaBot Trojan Returns To Banking Threat Landscape

ID: ee013d16-7c2a-55e0-a42d-ae66446cd6a4

STIX ID: report--ee013d16-7c2a-55e0-a42d-ae66446cd6a4

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

This Cyble report analyzes a newly resurfaced variant of the DanaBot banking trojan, detailing its UPX-packed Delphi loader, DLL export-based runtime behavior, anti-analysis techniques, TOR-capable C2 infrastructure, AES/RSA-based C2 protocol, and modular capabilities (credential theft, browser injection, keylogging, potential ransomware). The report provides multiple IOCs (hashes, IP addresses, and an .onion host), runtime analysis artifacts, and actionable recommendations for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.