A critical memory leak vulnerability in the command and control infrastructure of the DanaBot malware has exposed sensitive operational data belonging to cybercriminals, revealing hacker identities, cryptographic keys , and victim information spanning nearly three years of malicious operations.
See also: US: $10 million reward for information on RedLine malware operators

The vulnerability, dubbed “DanaBleed” by security researchers, resulted from a programming error introduced in June 2022 and persisted until early 2025, providing unprecedented insight into one of the most sophisticated banking trojans in the cybercrime ecosystem.
DanaBot first appeared in 2018 as a comprehensive Malware-as-a-Service designed to facilitate banking fraud, credential theft , and remote access operations.
The malware quickly gained a reputation for its modular architecture and sophisticated evasion techniques, allowing cybercriminals to conduct targeted attacks against financial institutions and individual users worldwide. Its versatility allowed malicious actors to deploy a variety of payloads, from keyloggers and screen capture tools to more advanced persistent access mechanisms.
Zscaler researchers identified the memory leak vulnerability while analyzing DanaBot version 2380, which introduced significant changes to the malware's communication protocol in June 2022.
See also: Honeywell: Ramnit malware infections are increasing
Researchers discovered that the vulnerability inadvertently leaked portions of the C2 server's process memory in responses to infected victims, comparable to the infamous Heartbleed vulnerability of 2014.

This omission provided security analysts with unprecedented access to DanaBot's inner workings, exposing critical information about the threat actors' infrastructure and methodologies.
The information leaks proved extensive and damaging to the cybercriminal's business, revealing usernames and IP addresses of threat actors, details of behind-the-scenes C2 server infrastructure, infection, malware version updates, and private cryptographic keys.
Perhaps most importantly, the vulnerability exposed victims' credentials and other stolen data, demonstrating the breadth of DanaBot's information-stealing capabilities
See also: Fake DocuSign pages distribute NetSupport RAT malware
The information gleaned from these memory leaks contributed valuable intelligence that likely aided law enforcement efforts, culminating in Operation Endgame and the indictment of 16 associated members in May 2025.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
