ESET has been monitoring Danabot since 2018. The malware, offered as a service, is known for stealing data and spreading ransomware. ESET analysis reveals the latest features and developers' business model. Among the most affected countries are Poland, Italy, Spain and Türkiye
ESET, a global European leader in the cybersecurity market, participated in a major international operation aimed at neutralizing the Danabot malware infrastructure. The action was coordinated by the U.S. Department of Justice, the FBI and the U.S. Department of Defense's Defense Criminal Investigative Service, with the support of Europol and Eurojust.
The US agencies worked in close collaboration with the Bundeskriminalamt (Germany), the Netherlands' National Police and the Australian Federal Police, along with private partners including Amazon, CrowdStrike, Flashpoint, Google, Intel471, PayPal, Proofpoint, Team Cymru and Zscaler.
ESET provided a significant contribution through the technical analysis of the malware and its backend infrastructure, as well as the identification of Danabot's Command and Control (C&C) servers.
ESET Research has been monitoring Danabot since 2018, analyzing active campaigns globally. Among the historically most affected countries are Poland, Italy, Spain and Türkiye. Born as an infostealer, Danabot has also frequently been used as a vector for the distribution of additional threats, including ransomware.
The operation – conducted as part of the global Operation Endgame initiative – led to the dismantling of critical infrastructure used for the spread of ransomware via malicious software. The joint intervention also allowed the identification of several individuals involved in the development, sale and management of Danabot.
“With Danabot now largely compromised, we take this opportunity to share our analysis of this malware-as-a-service operation, describing the malware's latest features, the authors' business model and the tools offered to affiliates,” explains Tomáš Procházka, ESET researcher involved in the investigation.
Danabot developers operate as a single entity, offering the malware for rent to affiliates, who in turn use it to operate autonomous botnets. The malware includes numerous advanced features:
– Data theft from browsers, email clients, FTP clients and other software;
– Keylogging e screen recording;
– Real-time remote control of infected systems;
– File grabbing, often aimed at the theft of cryptocurrency wallets;
– Support for Zeus-style webinject and form grabbing;
– Loading and execution of payloads chosen by the attacker.
ESET has also documented the use of Danabot for purposes other than data exfiltration alone. In documented cases, it has also been used to conduct DDoS attacks, such as the one aimed at the Ministry of Defense of Ukraine shortly after the 2022 Russian invasion.
Over time, affiliated cyber criminals have adopted different distribution methods. Recently, ESET identified the abuse of Google Ads, used to display apparently legitimate but actually malicious sponsored links. Such campaigns direct victims to fraudulent sites offering infected software or solutions for non-existent computer problems. Other techniques include fake software packages and sites that promise recovery of unclaimed funds.
The kit made available to affiliates includes an administration panel, a backconnect tool for real-time remote control and a proxy application to route communications between bots and C&C servers. Affiliates are responsible for creating new malware variants and spreading them through customized campaigns.
"It is not yet clear whether Danabot will be able to recover from this blow. The operation nevertheless inflicted substantial damage, leading to the unmasking of several individuals involved in its activities," concludes Procházka.
For technical insights and detailed analyses, please refer to the post "Danabot: Analyzing a fallen empire” published on the ESET Research blog, WeLiveSecurity.com. To stay updated on the latest news you can follow ESET Research on X (formerly known as Twitter), BlueSky e Mastodon.






