Description
DanaBot is a modular banking trojan focused on persistence and the collection of information that its operators can later monetize. Its campaigns use well crafted social engineering in low volume email deliveries, and its modular design downloads additional components that extend its stealing and remote monitoring capabilities.
Stats
- First seen
- January 2022
- Last seen
- October 2026
Also known as
Danabot
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.DanaBot |
| Document-Word.Trojan.DanaBot |
| Gen:Variant.Danabot.2 |
| Script-JS.Trojan.DanaBot |
| Script-WScript.Trojan.Danabot |
| Script-WScript.Trojan.DanaBot |
| Win32.Downloader.Danabot |
| Win32.Dropper.Danabot |
| Win32.Exploit.DanaBot |
| Win32.Infostealer.Danabot |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Win.Trojan.Danabot download attempt |