{"id":2758,"date":"2025-05-23T12:31:58","date_gmt":"2025-05-23T12:31:58","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=2758"},"modified":"2025-05-23T12:31:58","modified_gmt":"2025-05-23T12:31:58","slug":"danabot-malware-devs-contaminated-their-personal-pcs-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=2758","title":{"rendered":"DanaBot Malware Devs Contaminated Their Personal PCs \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>The U.S. authorities immediately unsealed felony prices towards 16 people accused of working and promoting <strong>DanaBot<\/strong>, a prolific pressure of information-stealing malware that has been bought on Russian cybercrime boards since 2018. The <strong>FBI<\/strong> says a more moderen model of DanaBot was used for espionage, and that lots of the defendants uncovered their real-life identities after unintentionally infecting their very own programs with the malware.<\/p>\n<div id=\"attachment_71354\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-71354\" decoding=\"async\" class=\" wp-image-71354\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/05\/danabot.png\" alt=\"\" width=\"749\" height=\"650\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/05\/danabot.png 817w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/05\/danabot-768x666.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/05\/danabot-782x679.png 782w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/p>\n<p id=\"caption-attachment-71354\" class=\"wp-caption-text\">DanaBot\u2019s options, as promoted on its help website. Picture: welivesecurity.com.<\/p>\n<\/div>\n<p>Initially <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.proofpoint.com\/us\/threat-insight\/post\/danabot-new-banking-trojan-surfaces-down-under-0\" target=\"_blank\" rel=\"noopener\">noticed<\/a> in Might 2018 by researchers on the electronic mail safety agency <strong>Proofpoint<\/strong>, DanaBot is a malware-as-a-service platform that focuses on credential theft and banking fraud.<\/p>\n<p>Immediately, the <strong>U.S. Division of Justice<\/strong> unsealed a felony criticism and indictment from 2022, which stated the FBI recognized at the least 40 associates who have been paying between $3,000 and $4,000 a month for entry to the data stealer platform.<\/p>\n<p>The federal government says the malware contaminated greater than 300,000 programs globally, inflicting estimated losses of greater than $50 million. The ringleaders of the DanaBot conspiracy are named as <strong>Aleksandr Stepanov<\/strong>, 39, a.okay.a. \u201c<strong>JimmBee<\/strong>,\u201d and <strong>Artem Aleksandrovich Kalinkin<\/strong>, 34, a.okay.a. \u201c<strong>Onix<\/strong>\u201d, each of Novosibirsk, Russia. Kalinkin is an IT engineer for the Russian state-owned power big <strong>Gazprom<\/strong>. His Fb profile identify is \u201cMaffiozi.\u201d<\/p>\n<p>In keeping with the FBI, there have been at the least two main variations of DanaBot; the primary was bought between 2018 and June 2020, when the malware stopped being supplied on Russian cybercrime boards. The federal government alleges that the second model of DanaBot \u2014 rising in January 2021 \u2014 was supplied to co-conspirators to be used in focusing on navy, diplomatic and non-governmental group computer systems in a number of nations, together with the US, Belarus, the UK, Germany, and Russia.<\/p>\n<p>\u201cUnindicted co-conspirators would use the Espionage Variant to compromise computer systems all over the world and steal delicate diplomatic communications, credentials, and different information from these focused victims,\u201d reads a grand jury indictment dated Sept. 20, 2022. \u201cThis stolen information included monetary transactions by diplomatic workers, correspondence regarding day-to-day diplomatic exercise, in addition to summaries of a selected nation\u2019s interactions with the US.\u201d<\/p>\n<p>The indictment says the FBI in 2022 seized servers utilized by the DanaBot authors to regulate their malware, in addition to the servers that saved stolen sufferer information. The federal government stated the server information additionally present quite a few cases through which the DanaBot defendants contaminated their very own PCs, ensuing of their credential information being uploaded to stolen information repositories that have been seized by the feds.<\/p>\n<p>\u201cIn some circumstances, such self-infections gave the impression to be intentionally completed with a view to take a look at, analyze, or enhance the malware,\u201d the felony criticism reads. \u201cIn different circumstances, the infections appeared to be inadvertent \u2013 one of many hazards of committing cybercrime is that criminals will typically infect themselves with their very own malware by mistake.\u201d<span id=\"more-71351\"\/><\/p>\n<div id=\"attachment_71359\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-71359\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-71359\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/05\/eset-danabotmap.png\" alt=\"\" width=\"750\" height=\"479\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/05\/eset-danabotmap.png 846w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/05\/eset-danabotmap-768x490.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/05\/eset-danabotmap-782x499.png 782w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\"\/><\/p>\n<p id=\"caption-attachment-71359\" class=\"wp-caption-text\">Picture: welivesecurity.com<\/p>\n<\/div>\n<p>A <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/usao-cdca\/pr\/16-defendants-federally-charged-connection-danabot-malware-scheme-infected-computers\" target=\"_blank\" rel=\"noopener\">assertion<\/a> from the DOJ says that as a part of immediately\u2019s operation, brokers with the <strong>Protection Felony Investigative Service<\/strong> (DCIS) seized the DanaBot management servers, together with dozens of digital servers hosted in the US. The federal government says it&#8217;s now working with trade companions to inform DanaBot victims and assist remediate infections. The assertion credit quite a few safety corporations with offering help to the federal government, together with <strong>ESET<\/strong>, <strong>Flashpoint<\/strong>, <strong>Google<\/strong>, <strong>Intel 471<\/strong>, <strong>Lumen<\/strong>, <strong>PayPal<\/strong>, <strong>Proofpoint<\/strong>, <strong>Group CYRMU<\/strong>, and <strong>ZScaler<\/strong>.<\/p>\n<p>It\u2019s not unparalleled for financially-oriented malicious software program to be repurposed for espionage. A variant of the <strong>ZeuS Trojan<\/strong>, which was utilized in numerous on-line banking assaults towards firms in the US and Europe between 2007 and at the least 2015, was for a time diverted to espionage duties by its creator.<\/p>\n<p>As detailed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2015\/08\/inside-the-100m-business-club-crime-gang\/\" target=\"_blank\" rel=\"noopener\">on this 2015 story,<\/a> the creator of the ZeuS trojan created a customized model of the malware to serve purely as a spying machine, which scoured contaminated programs in Ukraine for particular key phrases in emails and paperwork that will possible solely be present in labeled paperwork.<\/p>\n<p>The general public charging of the 16 DanaBot defendants comes a day after <strong>Microsoft<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/05\/21\/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer\/\" target=\"_blank\" rel=\"noopener\">joined<\/a> a slew of tech firms in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-seizes-domains-behind-major-information-stealing-malware-operation\" target=\"_blank\" rel=\"noopener\">disrupting the IT infrastructure<\/a> for an additional malware-as-a-service providing \u2014 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/eset-takes-part-global-operation-disrupt-lumma-stealer\/\" target=\"_blank\" rel=\"noopener\">Lumma Stealer<\/a>, which is likewise supplied to associates underneath tiered subscription costs starting from $250 to $1,000 monthly. Individually, Microsoft filed a civil lawsuit to grab management over 2,300 domains utilized by Lumma Stealer and its associates.<\/p>\n<p>Additional studying:<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/danabot-analyzing-fallen-empire\/\" target=\"_blank\" rel=\"noopener\">Danabot: Analyzing a Fallen Empire<\/a><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/danabot-launches-ddos-attack-against-ukrainian-ministry-defense\" target=\"_blank\" rel=\"noopener\">ZScaler weblog: DanaBot Launches DDoS Assault Towards the Ukrainian Ministry of Protection<\/a><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/flashpoint.io\/blog\/operation-endgame-danabot-malware\/\" target=\"_blank\" rel=\"noopener\">Flashpoint: Operation Endgame DanaBot Malware<\/a><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.team-cymru.com\/post\/inside-danabots-infrastructure-in-support-of-operation-endgame-ii\" target=\"_blank\" rel=\"noopener\">Group CYRMU: Inside DanaBot\u2019s Infrastructure: In Help of Operation Endgame II<\/a><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/usao-cdca\/media\/1401361\/dl?inline\" target=\"_blank\" rel=\"noopener\">March 2022 felony criticism v. Artem Aleksandrovich Kalinkin<\/a><\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/usao-cdca\/media\/1401356\/dl?inline\" target=\"_blank\" rel=\"noopener\">September 2022 grand jury indictment naming the 16 defendants<\/a><\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>The U.S. authorities immediately unsealed felony prices towards 16 people accused of working and promoting DanaBot, a prolific pressure of information-stealing malware that has been bought on Russian cybercrime boards since 2018. The FBI says a more moderen model of DanaBot was used for espionage, and that lots of the defendants uncovered their real-life identities [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2760,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2666,1003,2667,262,216,680,211],"class_list":["post-2758","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-danabot","tag-devs","tag-infected","tag-krebs","tag-malware","tag-pcs","tag-security"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/2758","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2758"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/2758\/revisions"}],"predecessor-version":[{"id":2759,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/2758\/revisions\/2759"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/2760"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2758"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2758"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2758"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-02 10:46:29 UTC -->