Drooid Logo
Back to today’s briefing

Story perspectives

DanaBot Malware Returns: Targets Cryptocurrency, Urges Cybersecurity Action

11/13/2025

50 4

1 of 1

Story summary
  • DanaBot banking malware resurfaced with variant 669, six months after its takedown during Operation Endgame.
  • DanaBot uses a hybrid command-and-control infrastructure, combining IP-based and Tor-hidden services.
  • It expands social engineering capabilities, employing spear-phishing emails to spread and deploy data harvesting and payload modules.
  • DanaBot targets cryptocurrency theft, configured to steal Bitcoin, Ethereum, Litecoin, and TRON.
  • The resurgence prompts stronger cybersecurity measures for individuals and financial institutions.