Close Menu
  • Home
  • AI
  • Big Data
  • Cloud Computing
  • iOS Development
  • IoT
  • IT/ Cybersecurity
  • Tech
    • Nanotechnology
    • Green Technology
    • Apple
    • Software Development
    • Software Engineering

Subscribe to Updates

Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

    What's Hot

    Was My TikTok Hacked? How to Get Back Into Your Account and Lock Down Sessions

    February 5, 2026

    PostgreSQL on Azure supercharged for AI

    February 5, 2026

    Valve’s Steam Machine has been delayed, and the RAM crisis will impact pricing

    February 5, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Big Tee Tech Hub
    • Home
    • AI
    • Big Data
    • Cloud Computing
    • iOS Development
    • IoT
    • IT/ Cybersecurity
    • Tech
      • Nanotechnology
      • Green Technology
      • Apple
      • Software Development
      • Software Engineering
    Big Tee Tech Hub
    Home»IT/ Cybersecurity»DanaBot malware is back to infecting Windows after 6-month break
    IT/ Cybersecurity

    DanaBot malware is back to infecting Windows after 6-month break

    big tee tech hubBy big tee tech hubNovember 12, 2025002 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    DanaBot malware is back to infecting Windows after 6-month break
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    DanaBot malware is back to infecting Windows after 6-month break

    The DanaBot malware has returned with a new version observed in attacks, six-months after law enforcement’s Operation Endgame disrupted its activity in May.

    According to security researchers at Zscaler ThreatLabz, there is a new variant of DanaBot, version 669, that has a command-and-control (C2) infrastructure using  Tor domains (.onion) and “backconnect” nodes.

    Zscaler also identified and listed several cryptocurrency addresses that threat actors are using to receive stolen funds, in BTC, ETH, LTC, and TRX.

    Wiz

    DanaBot was first disclosed by Proofpoint researchers as a Delphi-based banking trojan delivered via email and malvertising.

    It operated under a malware-as-a-service (MaaS) model, being rented to cybercriminals for a subscription fee.

    In the years that followed, the malware evolved into a modular information stealer and loader, targeting credentials and cryptocurrency wallet data stored in web browsers.

    The malware was used in numerous campaigns, some of which were large-scale, and reappeared occasionally from 2021 onward, remaining a steady threat to internet users.

    In May this year, an international law enforcement effort codenamed ‘Operation Endgame’ disrupted Danabot’s infrastructure and announced indictments and seizures, which significantly degraded its operations.

    However, according to Zscaler, Danabot is again active, with a rebuilt infrastructure. While the Danabot operation was down, many initial access brokers (IAB) pivoted to other malware.

    DanaBot resurfacing shows that cybercriminals are resilient in their activity as long as there is a financial incentive, despite a multi-month disruption, especially when core operators aren’t arrested.

    Typical initial access methods observed in DanaBot infections include malicious emails (via links or attachments), SEO poisoning, and malvertising campaigns, some of which led to ransomware.

    Organizations can defend against DanaBot attacks by adding to their blocklists the new indicators of compromise (IoCs) from Zscaler and by updating their security tools.


    Wiz

    It’s budget season! Over 300 CISOs and security leaders have shared how they’re planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

    Learn how top leaders are turning investment into measurable impact.



    Source link

    6month Break DanaBot infecting Malware Windows
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    tonirufai
    big tee tech hub
    • Website

    Related Posts

    Was My TikTok Hacked? How to Get Back Into Your Account and Lock Down Sessions

    February 5, 2026

    Analytics Context Engineering for LLM

    February 4, 2026

    FBI takes notorious RAMP ransomware forum offline

    February 3, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Was My TikTok Hacked? How to Get Back Into Your Account and Lock Down Sessions

    February 5, 2026

    PostgreSQL on Azure supercharged for AI

    February 5, 2026

    Valve’s Steam Machine has been delayed, and the RAM crisis will impact pricing

    February 5, 2026

    Xcode 26.3 adds agentic coding support

    February 5, 2026
    About Us
    About Us

    Welcome To big tee tech hub. Big tee tech hub is a Professional seo tools Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of seo tools, with a focus on dependability and tools. We’re working to turn our passion for seo tools into a booming online website. We hope you enjoy our seo tools as much as we enjoy offering them to you.

    Don't Miss!

    Was My TikTok Hacked? How to Get Back Into Your Account and Lock Down Sessions

    February 5, 2026

    PostgreSQL on Azure supercharged for AI

    February 5, 2026

    Subscribe to Updates

    Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

      • About Us
      • Contact Us
      • Disclaimer
      • Privacy Policy
      • Terms and Conditions
      © 2026 bigteetechhub.All Right Reserved

      Type above and press Enter to search. Press Esc to cancel.