Thursday, April 23, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

ESET participates in operation to disrupt the infrastructure of Danabot infostealer

May 23, 2025
in Artificial Intelligence, Cryptocurrencies, GlobeNewswire, Web3
Reading Time: 7 mins read
5
SHARES
245
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • ESET Research has been tracking Danabot’s activity since 2018 as part of a global effort that resulted in a major disruption of the malware’s infrastructure.
  • While primarily developed as an infostealer, Danabot also has been used to distribute additional malware, including ransomware.
  • Danabot’s authors promote their toolset through underground forums and offer various rental options to potential affiliates.
  • This ESET Research analysis covers the features used in the latest versions of the malware, the authors’ business model, and an overview of the toolset offered to affiliates.
  • Poland, Italy, Spain and Turkey are historically one of the most targeted countries by Danabot.

PRAGUE and BRATISLAVA, Czech Republic, May 22, 2025 (GLOBE NEWSWIRE) — ESET has participated in a major infrastructure disruption of the notorious infostealer, Danabot, by the US Department of Justice, the FBI, and US Department of Defense’s Defense Criminal Investigative Service. U.S. agencies were working closely with Germany’s Bundeskriminalamt, the Netherlands’ National Police, and the Australian Federal Police. ESET took part in the effort alongside Amazon, CrowdStrike, Flashpoint, Google, Intel471, PayPal, Proofpoint, Team Cymru and Zscaler. ESET Research, which has been tracking Danabot since 2018, contributed assistance that included providing technical analysis of the malware and its backend infrastructure, as well as identifying Danabot’s C&C servers. During that period, ESET analyzed various Danabot campaigns all over the world, with Poland, Italy, Spain and Turkey historically being one of the most targeted countries. The joint takedown effort also led to the identification of individuals responsible for Danabot development, sales, administration, and more.

“Since Danabot has been largely disrupted, we are using this opportunity to share our insights into the workings of this malware-as-a-service operation, covering the features used in the latest versions of the malware, the authors’ business model, and an overview of the toolset offered to affiliates. Apart from exfiltrating sensitive data, we have observed that Danabot is also used to deliver further malware, which can include ransomware, to an already compromised system,” says ESET researcher Tomáš Procházka, who investigated Danabot.

The authors of Danabot operate as a single group, offering their tool for rental to potential affiliates, who subsequently employ it for their malicious purposes by establishing and managing their own botnets. Danabot’s authors have developed a vast variety of features to assist customers with their malevolent motives. The most prominent features offered by Danabot include: the ability to steal various data from browsers, mail clients, FTP clients, and other popular software; keylogging and screen recording; real-time remote control of the victims’ systems; file grabbing; support for Zeus-like webinjects and form grabbing; and arbitrary payload upload and execution. Besides utilizing its stealing capabilities, ESET Research has observed a variety of payloads being distributed via Danabot over the years. Furthermore, ESET has encountered instances of Danabot being used to download ransomware onto already compromised systems.

In addition to typical cybercrime, Danabot has also been used in less conventional activities such as utilizing compromised machines for launching DDoS attacks… for example, a DDoS attack against Ukraine’s Ministry of Defense soon after the Russian invasion of Ukraine.

Throughout its existence, according to ESET monitoring, Danabot has been a tool of choice for many cybercriminals and each of them has used different means of distribution. Danabot’s developers even partnered with the authors of several malware cryptors and loaders, and offered special pricing for a distribution bundle to their customers, helping them with the process. Recently, out of all distribution mechanisms ESET observed, the misuse of Google Ads to display seemingly relevant, but actually malicious, websites among the sponsored links in Google search results stands out as one of the most prominent methods to lure victims into downloading Danabot. The most popular ploy is packing the malware with legitimate software and offering such a package through bogus software sites or websites falsely promising users to help them find unclaimed funds. The latest addition to these social engineering techniques are deceptive websites offering solutions for fabricated computer issues, whose only purpose is to lure victims into execution of a malicious command secretly inserted into the user’s clipboard.

The typical toolset provided by Danabot’s authors to their affiliates includes an administration panel application, a backconnect tool for real-time control of bots, and a proxy server application that relays the communications between the bots and the actual C&C server. Affiliates can choose from various options to generate new Danabot builds, and it’s their responsibility to distribute these builds through their own campaigns.

“It remains to be seen whether Danabot can recover from the takedown. The blow will, however, surely be felt, since law enforcement managed to unmask several individuals involved in the malware’s operations,” concludes Procházka.

For technical overview of Danabot and insight into its operation, check out ESET Research blogpost: “Danabot: Analyzing a fallen empire” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Worldwide Danabot detections as seen in ESET telemetry since 2018

Worldwide Danabot detections as seen in ESET telemetry since 2018

About ESET

ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown— securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com or follow our social media, podcasts and blogs.

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/2306cbf1-1ef7-4040-8c12-ca8be3cc6689

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.

ShareTweet1ShareSendShare2
Previous Post

KMBIO announces Private sale for its P2P Exchange that connects Crypto World with Real Life

Next Post

Maryna Karpenko Wins Top Industry Honors for Shaping Global Communication

Related Posts

Institutional Digital Asset Infrastructure: The Maturation of Yield Routing and Restaking Rails

NEW YORK CITY, NY / ACCESS Newswire / April 23, 2026 / Black Titan Corporation (NASDAQ:BTTC) Executive Summary As we enter the latter half of April 2026, the "DeFi-as-a-Service" (DaaS) ecosystem is experiencing a rapid horizontal expansion driven by global payment aggregators and institutional custodians. The narrative has decisively shifted...

Read moreDetails

Aokah Launches Explorer and Builder: The First AI-Powered Platform to Take Enterprises from GCC Strategy to Execution

Three global enterprises in consumer goods, diversified manufacturing, and logistics are already using Explorer and Builder to make faster, more defensible location decisions and build GCCs with execution confidenceNEW YORK, April 23, 2026 /PRNewswire/ -- Aokah, the GCC Operating Systemˢᴹ purpose-built to orchestrate Global Capability Centers from strategy through scale,...

Read moreDetails

Global Telecom Leaders to Convene in Singapore for Definitive Summit on AI-Native Transformation and Industry Reinvention

MUMBAI, India and SINGAPORE, April 23, 2026 /PRNewswire/ -- Twimbit, the global research and advisory firm, has finalized the strategic agenda for the Twimbit Telecom Summit & Awards 2026 , scheduled for 21 May 2026 at the Capitol Theatre, Singapore. This high-level forum serves as the industry's primary catalyst for addressing...

Read moreDetails

PixerLens and Tata Consultancy Services Partner to Deliver AI-Powered Application Intelligence on TCS SovereignSecure™ Cloud

PLEASANTON, Calif., April 23, 2026 /PRNewswire/ -- PixerLens, Inc. announces a strategic partnership with Tata Consultancy Services (TCS) to jointly deliver advanced AI-powered solutions to enterprises worldwide. As part of this partnership, PixerLens' AI platform, Annotet AI, will be deployed on the TCS SovereignSecure™ Cloud and made available to customers...

Read moreDetails

BE Semiconductor Industries N.V. Announces Q1-26 Results

Q1-26 Orders of € 269.7 Million Up 104.5% vs. Q1-25 Revenue of € 184.9 Million and Net Income of € 51.6 Million Up 28.3% and 63.8%, Respectively, vs. Q1-25 DUIVEN, the Netherlands, April 23, 2026 (GLOBE NEWSWIRE) -- BE Semiconductor Industries N.V. (the “Company" or "Besi") (Euronext Amsterdam: BESI; OTC...

Read moreDetails

74Software completes refinancing of its Term Loans and Revolving Credit Facility

Press Release 74Software completes refinancing of its Term Loans and Revolving Credit Facility Paris, April 23, 2026 – 74Software announces the completion of the refinancing of its syndicated bank facilities. The transaction refinances the Group’s existing bank indebtedness, comprising a €120 million revolving credit facility maturing in 2027, an €80...

Read moreDetails

Nokia Corporation Interim Report for Q1 2026

Nokia CorporationInterim report23 April 2026 at 08:00 EEST Nokia Corporation Interim Report for Q1 2026 Solid start to the year with strong growth in Optical Networks Q1 comparable net sales grew 4% y-o-y on a constant currency and portfolio basis (+2% reported). Network Infrastructure net sales grew 6% y-o-y on a...

Read moreDetails

Melexis: Transparency declaration by Invesco Ltd.

Melexis NV (Euronext Brussels: MELE)Press release – Regulated informationTessenderlo (BE), 23 April 2026 – 07:00 CET Disclosure of transparency notification (article 14, first paragraph, of the Law of 2 May 2007) Notification by Invesco Ltd. of 21 April 2026 Summary of the notification Melexis NV has received a transparency notification...

Read moreDetails

0G to Make Alibaba’s Qwen wModels Accessible to AI Agents via Blockchain Integration

San Francisco, CA, April 23, 2026 (GLOBE NEWSWIRE) -- AI agents can now directly access top-tier large language models on-chain for the first time. The collaboration between 0G Foundation and Alibaba Cloud marks a significant shift in artificial intelligence (AI) infrastructure, enabling autonomous AI agents to access the Qwen large...

Read moreDetails

STMicroelectronics Reports Q1 2026 Financial Results

PR No: C3392C STMicroelectronics Reports Q1 2026 Financial Results   Q126 net revenues at $3.10 billion U.S. GAAP Gross margin at 33.8%. Excluding the Purchase Price Allocation (PPA) effects from the acquisition of NXP’s MEMS sensor business, non-U.S. GAAP1 gross margin at 34.1% U.S. GAAP operating income at $70 million (non-U.S....

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • FlipHTML5’s Flipbook Maker Creates Interactive Digital Publications Easily

    8 shares
    Share 3 Tweet 2
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    97 shares
    Share 39 Tweet 24
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    159 shares
    Share 64 Tweet 40
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    53 shares
    Share 21 Tweet 13
  • Mango AI Unveils AI Kissing Generator Free for Seamless Kiss Animation

    5 shares
    Share 2 Tweet 1
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Institutional Digital Asset Infrastructure: The Maturation of Yield Routing and Restaking Rails
  • Aokah Launches Explorer and Builder: The First AI-Powered Platform to Take Enterprises from GCC Strategy to Execution
  • Global Telecom Leaders to Convene in Singapore for Definitive Summit on AI-Native Transformation and Industry Reinvention
  • PixerLens and Tata Consultancy Services Partner to Deliver AI-Powered Application Intelligence on TCS SovereignSecure™ Cloud
  • BE Semiconductor Industries N.V. Announces Q1-26 Results

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.