The infamous DanaBot botnet suffered a major disruption as part of an international law enforcement operation, which also included charges and arrest warrants against more than a dozen individuals.
See also: US: Charges against creator of Qakbot botnet

The takedown effort is part of Operation Endgame, which has previously also targeted malware families such as Lumma Stealer, Smokeloader, TrickBot , and Bumblebee.
Europol announced that in the latest phase of Operation Endgame, which targeted DanaBot and other malware families that resurfaced after previous takedown efforts, authorities in collaboration with the private sector sought to interrupt the ransomware at the source, taking down approximately 300 servers and 650 domains, while international arrest warrants were issued for 20 individuals.
As part of Operation Endgame, authorities seized a total of $24 million, $4 million of which came from the most recent operation.
See also: New HTTPBot Botnet Targets Windows Machines
The U.S. Department of Justice said Thursday that the DanaBot botnet was disrupted after infecting more than 300,000 computers worldwide, facilitating scams and ransomware attacks that caused at least $50 million.

The U.S. Department of Justice has unsealed indictments against 16 individuals allegedly involved in the development and distribution of DanaBot. Among the key suspects are Aleksandr Stepanov, 39, also known as JimmBee, and Artem Aleksandrovich Kalinkin, 34, also known as Onix, both of Novosibirsk, Russia.
Both remain at large, however, if ultimately prosecuted in the United States, Kalinkin faces up to 72 years for the charges he has been charged with, while Stepanov faces up to five years in prison.
Cybersecurity expert and blogger Brian Krebs noted that Kalinkin works as an IT engineer at state-owned Russian energy giant Gazprom. Court documents revealed that many of the cybercriminals were identified when they accidentally infected their own computers with the DanaBot malware.
See also: 2024: Cloudflare blocks record number of DDoS attacks
Based on the above, it becomes clear that Operation Endgame marks a significant milestone in the fight against digital crime, particularly with regard to botnets and ransomware attacks. The DanaBot botnet, like other similar malware, is often used as a tool for mass data theft, user fraud, and ransomware installation on computer systems.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
