logo
ESET participates in operation to disrupt the infrastructure of Danabot infostealer

ESET participates in operation to disrupt the infrastructure of Danabot infostealer

Business Upturn22-05-2025

ESET Research has been tracking Danabot's activity since 2018 as part of a global effort that resulted in a major disruption of the malware's infrastructure.
While primarily developed as an infostealer, Danabot also has been used to distribute additional malware, including ransomware.
Danabot's authors promote their toolset through underground forums and offer various rental options to potential affiliates.
This ESET Research analysis covers the features used in the latest versions of the malware, the authors' business model, and an overview of the toolset offered to affiliates.
Poland, Italy, Spain and Turkey are historically one of the most targeted countries by Danabot.
PRAGUE and BRATISLAVA, Czech Republic, May 22, 2025 (GLOBE NEWSWIRE) — ESET has participated in a major infrastructure disruption of the notorious infostealer, Danabot, by the US Department of Justice, the FBI, and US Department of Defense's Defense Criminal Investigative Service. U.S. agencies were working closely with Germany's Bundeskriminalamt, the Netherlands' National Police, and the Australian Federal Police. ESET took part in the effort alongside Amazon, CrowdStrike, Flashpoint, Google, Intel471, PayPal, Proofpoint, Team Cymru and Zscaler. ESET Research, which has been tracking Danabot since 2018, contributed assistance that included providing technical analysis of the malware and its backend infrastructure, as well as identifying Danabot's C&C servers. During that period, ESET analyzed various Danabot campaigns all over the world, with Poland, Italy, Spain and Turkey historically being one of the most targeted countries. The joint takedown effort also led to the identification of individuals responsible for Danabot development, sales, administration, and more.
'Since Danabot has been largely disrupted, we are using this opportunity to share our insights into the workings of this malware-as-a-service operation, covering the features used in the latest versions of the malware, the authors' business model, and an overview of the toolset offered to affiliates. Apart from exfiltrating sensitive data, we have observed that Danabot is also used to deliver further malware, which can include ransomware, to an already compromised system,' says ESET researcher Tomáš Procházka, who investigated Danabot.
The authors of Danabot operate as a single group, offering their tool for rental to potential affiliates, who subsequently employ it for their malicious purposes by establishing and managing their own botnets. Danabot's authors have developed a vast variety of features to assist customers with their malevolent motives. The most prominent features offered by Danabot include: the ability to steal various data from browsers, mail clients, FTP clients, and other popular software; keylogging and screen recording; real-time remote control of the victims' systems; file grabbing; support for Zeus-like webinjects and form grabbing; and arbitrary payload upload and execution. Besides utilizing its stealing capabilities, ESET Research has observed a variety of payloads being distributed via Danabot over the years. Furthermore, ESET has encountered instances of Danabot being used to download ransomware onto already compromised systems.
In addition to typical cybercrime, Danabot has also been used in less conventional activities such as utilizing compromised machines for launching DDoS attacks… for example, a DDoS attack against Ukraine's Ministry of Defense soon after the Russian invasion of Ukraine.
Throughout its existence, according to ESET monitoring, Danabot has been a tool of choice for many cybercriminals and each of them has used different means of distribution. Danabot's developers even partnered with the authors of several malware cryptors and loaders, and offered special pricing for a distribution bundle to their customers, helping them with the process. Recently, out of all distribution mechanisms ESET observed, the misuse of Google Ads to display seemingly relevant, but actually malicious, websites among the sponsored links in Google search results stands out as one of the most prominent methods to lure victims into downloading Danabot. The most popular ploy is packing the malware with legitimate software and offering such a package through bogus software sites or websites falsely promising users to help them find unclaimed funds. The latest addition to these social engineering techniques are deceptive websites offering solutions for fabricated computer issues, whose only purpose is to lure victims into execution of a malicious command secretly inserted into the user's clipboard.
The typical toolset provided by Danabot's authors to their affiliates includes an administration panel application, a backconnect tool for real-time control of bots, and a proxy server application that relays the communications between the bots and the actual C&C server. Affiliates can choose from various options to generate new Danabot builds, and it's their responsibility to distribute these builds through their own campaigns.
'It remains to be seen whether Danabot can recover from the takedown. The blow will, however, surely be felt, since law enforcement managed to unmask several individuals involved in the malware's operations,' concludes Procházka.
For technical overview of Danabot and insight into its operation, check out ESET Research blogpost: 'Danabot: Analyzing a fallen empire' on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.
Worldwide Danabot detections as seen in ESET telemetry since 2018
About ESET
ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown— securing businesses, critical infrastructure, and individuals. Whether it's endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts and blogs.
A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/2306cbf1-1ef7-4040-8c12-ca8be3cc6689
Disclaimer: The above press release comes to you under an arrangement with GlobeNewswire. Business Upturn takes no editorial responsibility for the same.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Scientists Startled by Discovery of Small Star Swimming Through Outer Layers of Another Larger Star
Scientists Startled by Discovery of Small Star Swimming Through Outer Layers of Another Larger Star

Yahoo

timea day ago

  • Yahoo

Scientists Startled by Discovery of Small Star Swimming Through Outer Layers of Another Larger Star

A team of researchers in China have discovered a stunning binary system in which a stellar object known as a pulsar orbited inside the outer layers of its companion star — which it accomplished after stripping its host's innards and dispersing them into space. The findings, detailed in a new study published in the journal Science, are an incredibly rare example of a "spider star" that preys on its companion, so-named because of the female arachnids that devour males after mating. And tantalizingly, the grisly scene is some of the best evidence yet of a stage of stellar evolution called the common envelope phase, which has never been directly observed by astronomers. Pulsars are rapidly spinning neutron stars, the incredibly dense stellar cores that are left over in the aftermath of a supernova. Everything about neutron stars exhaust superlatives — their gravity most of all. They are so tightly packed, containing more mass than our Sun inside a form just a dozen miles in radius, that all their atoms and their constituent protons and electrons have been crushed into neutrons, with just a teaspoon of this improbable matter weighing trillions of pounds. Their powerful magnetic fields, billions of times stronger than Earth's, unleash beams of radio waves into space along their poles. Further beggaring belief, some neutron stars become pulsars, which spin up to hundreds of times per second after siphoning material from a stellar companion, if it has one. Their sweeping beams of radiation, like cosmic lighthouses, look like a repeating signal to observers. The newly discovered pulsar, PSR J1928+1815, intrigued the astronomers because its radio pulses suggested that it was extremely close to its host, completing an orbit every 3.6 hours. They also noticed that for one-sixth of that orbit, the pulsar would vanish from view, indicating that the host was eclipsing it. "That's a large part of the orbit," coauthor Jin-Lin Han, a radio astronomer at the National Astronomical Observatories in Beijing, told Gizmodo. "That's strange, only a larger companion can do this." Over four and a half years, Han's team closely observed the system using the Five-hundred-meter Aperture Spherical Radio Telescope (FAST) in southern China, the largest and most powerful single-dish radio telescope in the world. Their observations revealed that the host star was between one to 1.6 times the mass of our Sun, while the pulsar was more likely 1.4 stellar masses. Determining the make of the host star, however, took some additional sleuthing. Its tight orbit and the fact that it was only detectable in radio wavelengths, Giz noted, ruled out its being a Sun-like star. And since it was large enough to eclipse the pulsar, it had to be something larger than a stellar remnant like another neutron star. That pointed to something altogether more spectacular: a helium star, created after the pulsar, when it was still an ordinary neutron star, tore off its host's layers and created a huge common envelope, a cloud of hydrogen gas that swallows both the stars. In this case, the poor star under attack managed to cling on to its evacuated innards for just 1,000 years — a blink in a stellar lifespan — before the whole, mighty envelope fell apart. Fleeting as it was, its impact is lasting: the friction exerted by the gases gradually nudged both stars closer together. Common envelopes are rare because the process of a neutron star stripping its companion, which causes it to spin and graduate to a pulsar, usually results in all the siphoned material being devoured. But if the companion is massive enough, much of it survives. The discovery marks the first spider star found orbiting a helium star. While the astronomers didn't get to witness the envelope in action, this is some of the most convincing evidence to date that this long-theorized stage of stellar evolution exists. In all, the team estimates that there're just 16 to 84 star systems like this one in the entire Milky Way — and, against all odds, we got to see one. More on space: Scientists Puzzled by Mysterious Motion in Atmosphere of Saturn's Moon

'Let's Move On': Musk Deflects Questions About Drug Use
'Let's Move On': Musk Deflects Questions About Drug Use

Yahoo

time2 days ago

  • Yahoo

'Let's Move On': Musk Deflects Questions About Drug Use

Elon Musk, left, and President Donald Trump, speak to reporters in the Oval Office of the White House in Washington, DC, on May 30, 2025. Credit - Kevin Dietsch—Getty Images Elon Musk's final hours working for President Donald Trump were spent in part by deflecting questions about his drug use, which a New York Times investigation on Friday revealed was far more extensive than previously known. Standing beside Trump in the Oval Office to mark his last day in government, Musk cut off a reporter for even mentioning the New York Times' reported allegations that he regularly consumed ketamine, ecstasy, and psychedelic mushrooms while traveling with Trump on the campaign trail last year. 'The New York Times. Is that the same publication that got a Pulitzer Prize for false reporting on Russiagate?' Musk said when asked about the report, alluding to conservative criticism of the Times' coverage of Russian interference in the 2016 US election. 'Let's move on.' Musk has had a ubiquitous presence at the White House over the past year, attending Cabinet meetings, appearing regularly with Trump in the Oval Office, and serving as the public face of the Department of Government Efficiency, a network of engineers tasked with rooting out waste, fraud, and abuse from the federal government. His role, while technically unpaid and temporary, grew in both scope and influence—often bypassing traditional bureaucratic channels. But as Musk's visibility rose, so did concerns about his behavior behind the scenes. The Times report described an increasingly erratic figure whose drug use went far beyond the occasional ketamine prescription he had previously disclosed. According to people familiar with his activities, he told associates that he was taking so much ketamine that it was damaging his bladder, a known consequence of chronic abuse. He also traveled with a daily medication box filled with roughly 20 pills, including Adderall, The Times reported. It remains unclear whether Musk was under the influence while in his government role. But some critics have noted his erratic behavior, such as his Nazi-like gesture at a rally, garbled answers during interviews, and frequent insults of top Trump officials. The White House declined to comment directly on the matter. Trump's deputy chief of staff Stephen Miller told reporters Friday that he has no concerns over Musk's alleged drug use. 'The drugs I'm concerned about are the drugs that are coming across the border from the criminal cartels that are killing hundreds of thousands of Americans,' Miller said. Musk has previously admitted his history of recreational drug use. In a 2024 interview with Don Lemon, he acknowledged he took 'a small amount' of prescribed ketamine to treat negative moods about once every two weeks, but that his heavy workload prevented him from using it too much. 'If you've used too much ketamine, you can't really get work done, and I have a lot of work,' he said. Musk announced on Friday that he plans to continue advising Trump and the U.S. DOGE Service even after he formally departs the government to focus more on his companies, which include Tesla and SpaceX, among others. During his time in the government, Musk oversaw DOGE's sweeping cuts to the federal workforce as part of the Trump Administration's efforts to vastly reduce federal spending. He had initially sought to cut $2 trillion from the nation's roughly $6.8 trillion federal budget, before walking back that figure. DOGE's website claims it has secured $175 billion in estimated savings, but media outlets have found its assertions to be exaggerated and misleading. TIME has not been able to independently verify those savings. 'I expect to continue to provide advice, whenever the President would like advice,' Musk said on Friday. 'I hope so,' Trump chimed in. 'I expect to remain a friend and an adviser,' Musk added, "and certainly, if there's anything the President wants me to do, I'm at the President's service." Write to Nik Popli at

Elon Musk's 'Intense' Drug Use Detailed in Bombshell New Report: Ecstasy, Mushrooms and Ketamine That Led to Bladder Issues
Elon Musk's 'Intense' Drug Use Detailed in Bombshell New Report: Ecstasy, Mushrooms and Ketamine That Led to Bladder Issues

Yahoo

time2 days ago

  • Yahoo

Elon Musk's 'Intense' Drug Use Detailed in Bombshell New Report: Ecstasy, Mushrooms and Ketamine That Led to Bladder Issues

A new report from The New York Times alleges that Elon Musk was abusing drugs as he ramped up support for Donald Trump's 2024 reelection campaign and donated millions to the cause. According to the Times, sources close to Musk allege that he was using ketamine frequently, sometimes daily, to the point that it began to damage his bladder. The 53-year-old tech billionaire was also said to use hallucinogenic mushrooms, ecstasy and the prescription stimulant Adderall, per the report. Elon Musk's time on the campaign trail for Donald Trump coincided with a period of increased drug abuse, according to new reporting by The New York Times. The Times cites sources close to the 53-year-old tech billionaire, who allege that Musk admitted to using ketamine frequently, sometimes daily, to the point that it had started to damage his bladder. A September 2022 study by the National Institute of Health notes that "significant side effects on the urinary tract are associated with frequent recreational ketamine use." Musk also allegedly used ecstasy and hallucinogenic mushrooms, and was reportedly known to travel with a pill box that contained Adderall, the ADHD treatment drug, which can be a stimulant for some. The Times' sources pin Musk's drug abuse to 2024, as the SpaceX CEO was ramping up support for Trump's reelection campaign, donating nearly $275 million. It's unclear whether or not the alleged habits followed him to Trump's White House, where he spearheaded the Department of Government Efficiency over the past four months. PEOPLE attempted to reach Musk and his lawyers for comment about the report. In a March 2024 interview with Don Lemon, Musk admitted to using ketamine, but said he only did the 'a small amount' of the drug about once every two weeks, as a prescribed treatment for depressive moods. 'If you've used too much ketamine, you can't really get work done, and I have a lot of work,' he said at the time. However, some friends and acquaintances remain skeptical about Musk's well-being. 'Elon has pushed the boundaries of his bad behavior more and more,' said Philip Low, a neuroscientist and former friend of the tech guru, who previously criticized him for the Nazi-like gesture he displayed onstage during Trump's second inauguration. Never miss a story — sign up for to stay up-to-date on the best of what PEOPLE has to offer​​, from celebrity news to compelling human interest stories. Whether or not Musk was using drugs while leading DOGE, his public displays of erratic behavior continued after he became a top White House adviser in January. At the Conservative Political Action Conference in February, Musk wielded a chainsaw on stage, engraved with the slogan 'Viva la libertad, carajo,' which is Spanish for 'Long live liberty, damn it.' The power tool had been gifted to him by Javier Milei, the president of Argentina. 'This is the chainsaw for bureaucracy,' he told the crowd. The new reporting about Musk's alleged drug use broke on the morning of Musk's final day as an official member of the Trump administration, hours before he was scheduled to do a farewell press conference with the president in the Oval Office about his time with DOGE. 'As my scheduled time as a Special Government Employee comes to an end, I would like to thank President @realDonaldTrump for the opportunity to reduce wasteful spending,' Musk posted to X on May 28. 'The @DOGE mission will only strengthen over time as it becomes a way of life throughout the government.' Musk's time at DOGE always had an endpoint — his 130-day mandate as a special government employee in the Trump administration expired on May 30. However, until his announcement on May 28, it was repeatedly said that he would remain heavily involved with the administration, merely stepping back to a less-central role. In an interview with CBS Sunday Morning that will air in full on June 1, Musk expressed his displeasure with his time in the political sector, noting that he felt all his work with DOGE could soon be undercut by Trump's sweeping budget legislation — titled the "Big, Beautiful Bill" — which passed in the House of Representatives on May 22. 'I was disappointed to see the massive spending bill, frankly, which increases the budget deficit, not just decreases it, and undermines the work that the DOGE team is doing,' he said. The "Big, Beautiful Bill" is funding its tax cuts and military spending in part by cutting some federal health and energy programs. However, it is also poised to add an estimated $3.8 trillion to the national deficit, according to the nonpartisan Congressional Budget Office. 'I think a bill can be big or it can be beautiful, but I don't know if it can be both," Musk said. Read the original article on People

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store