Story perspectives
DanaBot Malware Returns: Targets Cryptocurrency, Urges Cybersecurity Action
11/13/2025
50 4
1 of 1
Story summary
- DanaBot banking malware resurfaced with variant 669, six months after its takedown during Operation Endgame.
- DanaBot uses a hybrid command-and-control infrastructure, combining IP-based and Tor-hidden services.
- It expands social engineering capabilities, employing spear-phishing emails to spread and deploy data harvesting and payload modules.
- DanaBot targets cryptocurrency theft, configured to steal Bitcoin, Ethereum, Litecoin, and TRON.
- The resurgence prompts stronger cybersecurity measures for individuals and financial institutions.
