Latest news with #OperationEndgame


Channel Post MEA
5 days ago
- Business
- Channel Post MEA
ESET Plays Key Role in a Major International Operation to Disrupt Danabot
ESET has played a key role in a major international operation to disrupt Danabot, a notorious malware-as-a-service (MaaS) platform used to steal sensitive data and deliver ransomware. The coordinated takedown was led by the U.S. Department of Justice, the FBI, and the Defense Criminal Investigative Service, in partnership with Europol and global law enforcement agencies from Germany, the Netherlands, and Australia. ESET joined the effort alongside technology giants including Amazon, Google, CrowdStrike, Flashpoint, Intel471, PayPal, Proofpoint, Team Cymru, and Zscaler. ESET Research, which has tracked Danabot since 2018, provided in-depth technical analysis and helped identify the malware's command-and-control (C&C) servers and backend infrastructure. Danabot, historically active in countries such as Poland, Italy, Spain, and Turkey, operates as a single developer group offering its toolkit to affiliates. These affiliates deploy their own botnets to exfiltrate data, deliver further malware, and even launch DDoS attacks. ESET's Tomáš Procházka noted the malware's extensive features, including keylogging, browser and software credential theft, screen recording, remote system control, and payload delivery—often ransomware. The takedown is part of Operation Endgame, an ongoing initiative to dismantle cybercriminal infrastructure. Authorities also identified individuals involved in Danabot's development, sales, and operation, dealing a significant blow to its network. ESET reports that Danabot's authors had commercialized their toolkit by bundling it with malware loaders and cryptors, offering discounted distribution packages. One of the malware's most prominent infection tactics was the abuse of Google Ads to promote fake software sites, luring victims into downloading malware disguised as legitimate software. 'The scale of disruption to Danabot remains to be seen, but unmasking those behind it is a substantial victory for the cybersecurity community,' said Procházka. This operation marks a critical step in the global fight against organized cybercrime, with ESET reaffirming its commitment to collaboration and threat intelligence sharing. 0 0


Mid East Info
5 days ago
- Business
- Mid East Info
ESET participates in operation to disrupt the infrastructure of Danabot infostealer - Middle East Business News and Information
ESET Research has been tracking Danabot's activity since 2018 as part of a global effort that resulted in a major disruption of the malware's infrastructure. While primarily developed as an infostealer, Danabot also has been used to distribute additional malware, including ransomware. Danabot's authors promote their toolset through underground forums and offer various rental options to potential affiliates. This ESET Research analysis covers the features used in the latest versions of the malware, the authors' business model, and an overview of the toolset offered to affiliates. Poland, Italy, Spain and Turkey are historically one of the most targeted countries by Danabot. ESET has participated in a major infrastructure disruption of the notorious infostealer, Danabot, by the US Department of Justice, the FBI, and US Department of Defense's Defense Criminal Investigative Service. U.S. agencies were working closely with Germany's Bundeskriminalamt, the Netherlands' National Police, and the Australian Federal Police . ESET took part in the effort alongside Amazon, CrowdStrike, Flashpoint, Google, Intel471, PayPal, Proofpoint, Team Cymru and Zscaler. ESET Research, which has been tracking Danabot since 2018, contributed assistance that included providing technical analysis of the malware and its backend infrastructure, as well as identifying Danabot's C&C servers. During that period, ESET analyzed various Danabot campaigns all over the world, with Poland, Italy, Spain and Turkey historically being one of the most targeted countries. The joint takedown effort also led to the identification of individuals responsible for Danabot development, sales, administration, and more. These law enforcement operations were conducted under Operation Endgame — an ongoing global initiative aimed at identifying, dismantling, and prosecuting cybercriminal networks. Coordinated by Europol and Eurojust, the operation successfully took down critical infrastructure used to deploy ransomware through malicious software. 'Since Danabot has been largely disrupted, we are using this opportunity to share our insights into the workings of this malware-as-a-service operation, covering the features used in the latest versions of the malware, the authors' business model, and an overview of the toolset offered to affiliates. Apart from exfiltrating sensitive data, we have observed that Danabot is also used to deliver further malware, which can include ransomware, to an already compromised system,' says ESET researcher Tomáš Procházka, who investigated Danabot. The authors of Danabot operate as a single group, offering their tool for rental to potential affiliates, who subsequently employ it for their malicious purposes by establishing and managing their own botnets. Danabot's authors have developed a vast variety of features to assist customers with their malevolent motives. The most prominent features offered by Danabot include: the ability to steal various data from browsers, mail clients, FTP clients, and other popular software; keylogging and screen recording; real-time remote control of the victims' systems; file grabbing (commonly used for stealing cryptocurrency wallets); support for Zeus-like webinjects and form grabbing; and arbitrary payload upload and execution. Besides utilizing its stealing capabilities, ESET Research has observed a variety of payloads being distributed via Danabot over the years. Furthermore, ESET has encountered instances of Danabot being used to download ransomware onto already compromised systems. In addition to typical cybercrime, Danabot has also been used in less conventional activities such as utilizing compromised machines for launching DDoS attacks… for example, a DDoS attack against Ukraine's Ministry of Defense soon after the Russian invasion of Ukraine. Throughout its existence, according to ESET monitoring, Danabot has been a tool of choice for many cybercriminals and each of them has used different means of distribution. Danabot's developers even partnered with the authors of several malware cryptors and loaders, and offered special pricing for a distribution bundle to their customers, helping them with the process. Recently, out of all distribution mechanisms ESET observed, the misuse of Google Ads to display seemingly relevant, but actually malicious, websites among the sponsored links in Google search results stands out as one of the most prominent methods to lure victims into downloading Danabot. The most popular ploy is packing the malware with legitimate software and offering such a package through bogus software sites or websites falsely promising users to help them find unclaimed funds. The latest addition to these social engineering techniques are deceptive websites offering solutions for fabricated computer issues, whose only purpose is to lure victims into execution of a malicious command secretly inserted into the user's clipboard. The typical toolset provided by Danabot's authors to their affiliates includes an administration panel application, a backconnect tool for real-time control of bots, and a proxy server application that relays the communications between the bots and the actual C&C server. Affiliates can choose from various options to generate new Danabot builds, and it's their responsibility to distribute these builds through their own campaigns. 'It remains to be seen whether Danabot can recover from the takedown. The blow will, however, surely be felt, since law enforcement managed to unmask several individuals involved in the malware's operations,' concludes Procházka. For technical overview of Danabot and insight into its operation, check out ESET Research blogpost: 'Danabot: Analyzing a fallen empire' on Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research. About ESET ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown— securing businesses, critical infrastructure, and individuals. Whether it's endpoint, cloud or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit or follow our social media, podcasts and blogs.


Economic Times
24-05-2025
- Economic Times
EU, US authorities take down malware network
European, American and Canadian authorities have taken down over 300 servers worldwide and issued international arrest warrants against 20 suspects in a crackdown on malware, EU agency for criminal justice cooperation Eurojust said in a statement, the latest phase in Operation Endgame. By the numbers German, French, Dutch, Danish, British, American and Canadian authorities joined forces this week against the world's most dangerous malware variants and the perpetrators behind them. More than three dozen suspects were identified and 20 individuals criminally charged. Over 300 servers worldwide were taken down, 650 domains were neutralised and 3.5 million euros in cryptocurrency were seized. The actions follow efforts in May 2024, which had been the largest-ever operation against botnets. In total, 21.2 million euros have been seized during the an operation started in 2024. Context The malware taken down this week is known as "initial access malware." It is used for initial infection, helping cybercriminals to enter victims' systems unnoticed and load more malware onto their devices, such as ransomware. What's next Operation Endgame will continue with follow-up actions announced on the dedicated website from the international coalition. Several key suspects behind the malware operations are subject to international and public appeals. The German authorities will include eighteen of them on the EU Most Wanted list on Friday.


AsiaOne
24-05-2025
- AsiaOne
EU and US authorities take down malware network, Digital News
PARIS — European, American and Canadian authorities have taken down over 300 servers worldwide and issued international arrest warrants against 20 suspects in a crackdown on malware, EU agency for criminal justice co-operation Eurojust said in a statement, the latest phase in Operation Endgame. By the numbers German, French, Dutch, Danish, British, American and Canadian authorities joined forces this week against the world's most dangerous malware variants and the perpetrators behind them. More than three dozen suspects were identified and 20 individuals criminally charged. Over 300 servers worldwide were taken down, 650 domains were neutralised and 3.5 million euros (S$5.12 million) in cryptocurrency were seized. The actions follow efforts in May 2024, which had been the largest-ever operation against botnets. In total, 21.2 million euros have been seized during the operation started in 2024. Context The malware taken down this week is known as "initial access malware." It is used for initial infection, helping cybercriminals to enter victims' systems unnoticed and load more malware onto their devices, such as ransomware. What's next Operation Endgame will continue with follow-up actions announced on the dedicated website from the international coalition. Several key suspects behind the malware operations are subject to international and public appeals. The German authorities will include eighteen of them on the EU Most Wanted list on Friday (May 23). [[nid:717098]]


Time of India
24-05-2025
- Time of India
EU, US authorities take down malware network
European, American and Canadian authorities have taken down over 300 servers worldwide and issued international arrest warrants against 20 suspects in a crackdown on malware, EU agency for criminal justice cooperation Eurojust said in a statement, the latest phase in Operation Endgame . By the numbers German, French, Dutch, Danish, British, American and Canadian authorities joined forces this week against the world's most dangerous malware variants and the perpetrators behind them. Play Video Pause Skip Backward Skip Forward Unmute Current Time 0:00 / Duration 0:00 Loaded : 0% 0:00 Stream Type LIVE Seek to live, currently behind live LIVE Remaining Time - 0:00 1x Playback Rate Chapters Chapters Descriptions descriptions off , selected Captions captions settings , opens captions settings dialog captions off , selected Audio Track default , selected Picture-in-Picture Fullscreen This is a modal window. Beginning of dialog window. Escape will cancel and close the window. Text Color White Black Red Green Blue Yellow Magenta Cyan Opacity Opaque Semi-Transparent Text Background Color Black White Red Green Blue Yellow Magenta Cyan Opacity Opaque Semi-Transparent Transparent Caption Area Background Color Black White Red Green Blue Yellow Magenta Cyan Opacity Transparent Semi-Transparent Opaque Font Size 50% 75% 100% 125% 150% 175% 200% 300% 400% Text Edge Style None Raised Depressed Uniform Drop shadow Font Family Proportional Sans-Serif Monospace Sans-Serif Proportional Serif Monospace Serif Casual Script Small Caps Reset restore all settings to the default values Done Close Modal Dialog End of dialog window. by Taboola by Taboola Sponsored Links Sponsored Links Promoted Links Promoted Links You May Like Buy Brass Idols - Handmade Brass Statues for Home & Gifting Luxeartisanship Buy Now Undo More than three dozen suspects were identified and 20 individuals criminally charged. Over 300 servers worldwide were taken down, 650 domains were neutralised and 3.5 million euros in cryptocurrency were seized. The actions follow efforts in May 2024, which had been the largest-ever operation against botnets. Live Events In total, 21.2 million euros have been seized during the an operation started in 2024. Discover the stories of your interest Blockchain 5 Stories Cyber-safety 7 Stories Fintech 9 Stories E-comm 9 Stories ML 8 Stories Edtech 6 Stories Context The malware taken down this week is known as " initial access malware ." It is used for initial infection, helping cybercriminals to enter victims' systems unnoticed and load more malware onto their devices, such as ransomware. What's next Operation Endgame will continue with follow-up actions announced on the dedicated website from the international coalition. Several key suspects behind the malware operations are subject to international and public appeals. The German authorities will include eighteen of them on the EU Most Wanted list on Friday.