logo
ESET participates in operation to disrupt the infrastructure of Danabot infostealer

ESET participates in operation to disrupt the infrastructure of Danabot infostealer

Yahoo22-05-2025

ESET Research has been tracking Danabot's activity since 2018 as part of a global effort that resulted in a major disruption of the malware's infrastructure.
While primarily developed as an infostealer, Danabot also has been used to distribute additional malware, including ransomware.
Danabot's authors promote their toolset through underground forums and offer various rental options to potential affiliates.
This ESET Research analysis covers the features used in the latest versions of the malware, the authors' business model, and an overview of the toolset offered to affiliates.
Poland, Italy, Spain and Turkey are historically one of the most targeted countries by Danabot.
PRAGUE and BRATISLAVA, Czech Republic, May 22, 2025 (GLOBE NEWSWIRE) -- ESET has participated in a major infrastructure disruption of the notorious infostealer, Danabot, by the US Department of Justice, the FBI, and US Department of Defense's Defense Criminal Investigative Service. U.S. agencies were working closely with Germany's Bundeskriminalamt, the Netherlands' National Police, and the Australian Federal Police. ESET took part in the effort alongside Amazon, CrowdStrike, Flashpoint, Google, Intel471, PayPal, Proofpoint, Team Cymru and Zscaler. ESET Research, which has been tracking Danabot since 2018, contributed assistance that included providing technical analysis of the malware and its backend infrastructure, as well as identifying Danabot's C&C servers. During that period, ESET analyzed various Danabot campaigns all over the world, with Poland, Italy, Spain and Turkey historically being one of the most targeted countries. The joint takedown effort also led to the identification of individuals responsible for Danabot development, sales, administration, and more.
'Since Danabot has been largely disrupted, we are using this opportunity to share our insights into the workings of this malware-as-a-service operation, covering the features used in the latest versions of the malware, the authors' business model, and an overview of the toolset offered to affiliates. Apart from exfiltrating sensitive data, we have observed that Danabot is also used to deliver further malware, which can include ransomware, to an already compromised system,' says ESET researcher Tomáš Procházka, who investigated Danabot.
The authors of Danabot operate as a single group, offering their tool for rental to potential affiliates, who subsequently employ it for their malicious purposes by establishing and managing their own botnets. Danabot's authors have developed a vast variety of features to assist customers with their malevolent motives. The most prominent features offered by Danabot include: the ability to steal various data from browsers, mail clients, FTP clients, and other popular software; keylogging and screen recording; real-time remote control of the victims' systems; file grabbing; support for Zeus-like webinjects and form grabbing; and arbitrary payload upload and execution. Besides utilizing its stealing capabilities, ESET Research has observed a variety of payloads being distributed via Danabot over the years. Furthermore, ESET has encountered instances of Danabot being used to download ransomware onto already compromised systems.
In addition to typical cybercrime, Danabot has also been used in less conventional activities such as utilizing compromised machines for launching DDoS attacks... for example, a DDoS attack against Ukraine's Ministry of Defense soon after the Russian invasion of Ukraine.
Throughout its existence, according to ESET monitoring, Danabot has been a tool of choice for many cybercriminals and each of them has used different means of distribution. Danabot's developers even partnered with the authors of several malware cryptors and loaders, and offered special pricing for a distribution bundle to their customers, helping them with the process. Recently, out of all distribution mechanisms ESET observed, the misuse of Google Ads to display seemingly relevant, but actually malicious, websites among the sponsored links in Google search results stands out as one of the most prominent methods to lure victims into downloading Danabot. The most popular ploy is packing the malware with legitimate software and offering such a package through bogus software sites or websites falsely promising users to help them find unclaimed funds. The latest addition to these social engineering techniques are deceptive websites offering solutions for fabricated computer issues, whose only purpose is to lure victims into execution of a malicious command secretly inserted into the user's clipboard.
The typical toolset provided by Danabot's authors to their affiliates includes an administration panel application, a backconnect tool for real-time control of bots, and a proxy server application that relays the communications between the bots and the actual C&C server. Affiliates can choose from various options to generate new Danabot builds, and it's their responsibility to distribute these builds through their own campaigns.
'It remains to be seen whether Danabot can recover from the takedown. The blow will, however, surely be felt, since law enforcement managed to unmask several individuals involved in the malware's operations,' concludes Procházka.
For technical overview of Danabot and insight into its operation, check out ESET Research blogpost: 'Danabot: Analyzing a fallen empire' on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.
About ESET
ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown— securing businesses, critical infrastructure, and individuals. Whether it's endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts and blogs.
A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/2306cbf1-1ef7-4040-8c12-ca8be3cc6689
CONTACT: Media contact: Jessica Beffa jessica.beffa@eset.com 720-413-4938

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

IPTV USA vs. Streaming Giants: Is IPTV Still Worth It in 2025?
IPTV USA vs. Streaming Giants: Is IPTV Still Worth It in 2025?

Time Business News

time5 hours ago

  • Time Business News

IPTV USA vs. Streaming Giants: Is IPTV Still Worth It in 2025?

The rise of IPTV USA has sparked debate among American viewers. In a world dominated by streaming giants like Netflix, Hulu, and Disney+, where does IPTV fit in? Is it a better choice than the mainstream platforms? In this guide, we'll break down the differences, benefits, and why IPTV may still be the smartest streaming decision in 2025. In fact, according to a recent review by the Jerusalem Post, the top rated IPTV services in the USA are gaining traction due to their flexibility and content variety. While traditional streaming services offer curated content libraries, IPTV (Internet Protocol Television) delivers live channels — including sports, news, international stations, and video-on-demand — via the internet. This gives IPTV users access to: 24/7 live TV streaming Global content in multiple languages Pay-per-view events Thousands of movies and series Sports coverage not available on Netflix or Prime Unlike Netflix or Hulu, which offer only specific content and require separate subscriptions for live sports or cable-like experiences, IPTV consolidates everything into one powerful platform. With one subscription, you can: Watch CNN, ESPN, FOX, and BBC live Access HBO-style movies and Netflix-like series Use your Firestick, Smart TV, or mobile to stream from anywhere IPTV USA : ~$15/month (including live + VOD) : ~$15/month (including live + VOD) Netflix Premium : ~$20/month (VOD only) : ~$20/month (VOD only) Disney+ + Hulu + ESPN: $13–20/month (still no international live TV) Best IPTV for USA with full content access Xtreme HD IPTV offers a massive channel library, 4K streams, and stable access on Firestick. Whether you want NFL games, UK documentaries, or Bollywood cinema — it's all there. Easy IPTV solution for American families CatchOn TV is designed with usability in mind. A great fit for families, it delivers a full VOD library, live channels, and multi-device compatibility — including Smart TVs and smartphones. Parental control, catch-up, live TV & VOD menus Android, iOS, Smart TV, Firestick Premium IPTV interface with EPG and playlist management Optimized for Firestick and Android TV Simple Smart TV interface No sideloading required Settings > My Fire TV > Developer Options Enable 'Apps from Unknown Sources' Install Downloader Enter the IPTV app URL (APK) Add playlist/M3U/Xtream codes 🔥 Try it with: VPNs make your IPTV experience smoother, safer, and more private. They: Bypass ISP throttling Unlock geo-restricted content Protect your IP address Absolutely. IPTV USA offers a flexible, content-rich experience that streaming giants simply can't match — especially if you're a fan of live sports, international news, and budget-friendly access. Pair IPTV with a Firestick and a secure VPN, and you're not just cutting the cord — you're cutting through the noise. #IPTVUSA #BestIPTV2025 #IPTVvsNetflix #FirestickIPTV #StreamingRevolution #IPTVAppsUSA TIME BUSINESS NEWS

GameChat on Nintendo Switch 2 Makes Playing Games with Friends Hectic as Hell
GameChat on Nintendo Switch 2 Makes Playing Games with Friends Hectic as Hell

Gizmodo

time10 hours ago

  • Gizmodo

GameChat on Nintendo Switch 2 Makes Playing Games with Friends Hectic as Hell

In usual Nintendo fashion, the Switch 2 isn't making online play easier to access; it's making it stranger by far. GameChat, the online video chat functionality for Switch 2, lets you stream your friends' gameplay and friends' faces to your own game system while you play. Nintendo is devoting a hefty amount of system power to this feature, and the result is games that are far more chaotic than without it. That is all to say, I enjoy the hell out of it—at least what it accomplishes despite low-resolution picture quality. GameChat is a heavy dose of Discord-like functionality for Nintendo's handheld. You can talk over voice chat with up to 12 other people using the Switch 2's built-in microphone. This means you could see your friend's perspective as they bully you with red shell after red shell in Mario Kart World. But it also means you can watch as they play an entirely different game. You can have up to four of these streams running at once; the on-screen interface resembles what you'd find in your typical video calling app like Zoom or Microsoft Teams, with everyone streamed in their own respective window. See Nintendo Switch 2 at Walmart Finally, there's the Nintendo Switch 2 Camera. This 1080p stand-up webcam sits on your TV stand and faces toward the player. If playing in two of the main GameChat modes, either 'Standard' or 'Expand Main Screen,' you'll see your friend's streams and their mugs on top of them. Nintendo told us you can't move the stream window (yours or another person's) away from the right corner. If you want to shrink them to help see more of their screen, you'll need your fellow player to physically move their camera farther away to capture less of their body. I couldn't imagine a 1080p webcam and small in-built microphone would be quality enough to pick up my mug and voice with any amount of fidelity. As I sat down three feet from the TV stand bedecked with the Switch 2 dock, I started talking with two other people in different parts of the room—plus one player chiming in remotely online. We were inundated with a wave of chatter as several people tried to talk over each other. The audio wasn't exactly pitch-perfect. Everybody was talking to their console several feet away. Once the gabbing calmed a bit, I could start to make out different voices. The 40-minute online demo didn't offer enough time to truly test out latency or test how far from the mic you can be before you completely lose audio quality. We did get to test out how this looked while playing The Legend of Zelda: Four Swords through Nintendo's + Expansion Pack, a Nintendo Game Boy Advance game that was notoriously difficult to play together back in the days when you needed several link cables. I could see what every other player was doing on their screens. The noise, the cameras, and the screens all added to the sense of chaos as every one of our players started smacking each other with swords, rebounding off each other, and sending all of us tumbling to our collective doom on every moving platform. If co-op with your friends was already chaotic before you could literally screen cheat on each other's gameplay, then GameChat merely creates anarchy. The functionality is actually more endearing than the camera specs. In certain games, including Mario Kart World and Super Mario Party: Jamboree, the camera will actually display your face above your character. This works both online and with each of you on the couch. In Mario Kart World, when you get beaned by a red shell, your camera will spin as your character spins out. Seeing your compatriot's twisted expression as you send a blue shell their way is priceless, especially since you no longer have to look away from the screen to witness their agony. Nintendo knows it can get away with hardware limitations so long as the features remain fun. Still, I would like to see some actual fidelity with a kind of hardware—webcams—we're already intimately familiar with. The $55 Switch 2 camera combined with the handheld's software can crop out a background, offering a morsel of more screen real estate. In our short demo, the camera struggled to separate our bodies from the sofa we were sitting on. Even when it found the right shape of my body, the image appeared jagged on-screen. It's a factor of using a webcam that records at such a low resolution, but I couldn't get over the general unappealing look of each image. The image quality was dull and washed out and resembled a cheap $20 web. GameChat with video is mainly supposed to work in docked mode, though it is usable in handheld mode if you want to connect the camera. Currently, there's the 480p Piranha Plant camera from Hori that can also attach directly to the console through its top USB-C port. This may allow for better picture quality if the camera no longer has to zoom in on each person sitting several feet away. There's a chance a better webcam will improve the picture quality. Nintendo has yet to say which third-party webcams the Switch 2 supports. If I had a better-looking webcam, one dressed up like Lakitu from Super Mario 64 holding a camera, it would be the perfect accessory to bring more couch co-op chaos to Nintendo's handheld. See Nintendo Switch 2 at Walmart

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store