The infamous DanaBot malware appears to have not said its last word. Six months after the successful Operation Endgame — an international effort by authorities aimed at dismantling the malware network — security researchers have identified a new variant , active in recent attacks.
According to a report by Zscaler’s ThreatLabz team , the updated version, with version number 669 , features a completely rebuilt command and control (C2) infrastructure , based on Tor domains (.onion) and “backconnect” nodes — a technique that makes tracing the activity nearly impossible. Zscaler also recorded a number of cryptocurrency addresses (BTC, ETH, LTC, TRX) that the perpetrators use to launder the stolen funds.
From banking trojan to sophisticated cybercrime tool
DanaBot first appeared in 2018, when Proofpoint classified it as a banking trojan that targets users' financial information. It was developed in Delphi and initially spread through phishing emails and malicious advertisements (malvertising).
See also: 'Maverick' malware targets bank customers in Brazil via WhatsApp

DanaBot operated under the Malware-as-a-Service (MaaS) — essentially, a kind of “subscription service” for cybercriminals who wanted to infect systems without writing any code themselves. The malware’s customers paid for access to servers, support, and updates, just as they would for any SaaS product.
Over the years, DanaBot has evolved into a modular platform capable of stealing credentials, cryptocurrency wallet files, and installing additional payloads, depending on the needs of each campaign. Its versions combine loader, infostealer , and spyware, making it one of the most versatile tools in the world of cybercrime.
Operation Endgame and the temporary "ceasefire"
In May 2025, law enforcement conducted Operation Endgame, a large-scale operation targeting multiple malware networks, including DanaBot. Servers, domains , and arrests in several countries, causing a significant disruption to the malware's operations.
This action resulted in the DanaBot network being frozen for months, while several “initial access brokers” (IABs) —the brokers who sell access to infected systems—temporarily turned to other tools, such as RedLine Stealer or Vidar.
However, as recent findings show, the key operators of DanaBot were not caught, allowing the software to regroup and resurface with an improved technological infrastructure.
See also: Rhadamanthys infostealer: Sudden shutdown

Email, SEO, and Malicious Advertising Attacks
The new version of DanaBot follows well-known but effective tactics to infiltrate target systems. Researchers have observed campaigns that leverage:
- Phishing emails with malicious attachments or links,
- SEO poisoning, where legitimate searches lead to infected websites,
- Malicious ads that redirect the user to malware installation websites.
In several cases, these infections act as a prelude to ransomware attacks, with DanaBot providing the initial access to other criminal groups.
Resilience and motivation: Why the threat doesn't go away
The reemergence of DanaBot highlights a critical reality of modern cyberspace: as long as there is a financial incentive, crime thrives. Despite international cooperation and the successes of authorities, perpetrators who remain uncaught can rebuild their infrastructure in a matter of months.
As Zscaler points out, this phenomenon demonstrates the dynamic nature of cybercrime — a constant “cat and mouse game” between attackers and defenders.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: GootLoader: New hiding technique on WordPress websites

How can organizations protect themselves?
To reduce the risk of infection, businesses and users should:
- They immediately update security tools and antivirus systems.
- They are adding the new indicators of compromise (IoCs) from Zscaler to their block lists.
- They train staff in recognizing phishing emails and suspicious advertisements.
- They implement Zero Trust policies to restrict access to critical infrastructure.
DanaBot may be just one example of many, but its return makes it clear: the digital threat is not dying, it is simply evolving.
Source: www.bleepingcomputer.com
