Law enforcement agencies have successfully disrupted one of the most sophisticated malware-as-a-service platforms operating in 2025, dealing a significant blow to the DanaBot botnet through Operation Endgame II.
The coordinated international effort targeted a criminal infrastructure that maintained an average of 150 active command-and-control servers daily while compromising approximately 1,000 victims across more than 40 countries.
This takedown represents one of the most comprehensive actions against cybercriminal infrastructure to date, demonstrating the effectiveness of collaborative efforts between security researchers, industry partners, and law enforcement agencies.
DanaBot first emerged in 2018 as a banking trojan designed primarily for financial credential theft, but has since evolved into a versatile and persistent threat capable of supporting a wide range of malicious activities.
Initially reported by Proofpoint researchers, the malware transformed from a simple banking trojan into a sophisticated platform used for information stealing, establishing initial access for ransomware operations, and delivering secondary payloads such as Latrodectus malware.
This evolution positioned DanaBot as a critical component in the modern cybercrime ecosystem, where threat actors increasingly rely on specialized tools for different phases of their attack campaigns.
Team Cymru analysts and researchers, working alongside Black Lotus Labs, identified the full scope of DanaBot’s infrastructure through extensive collaboration with industry peers and law enforcement agencies.
Their investigation revealed that DanaBot operated as one of the largest malware-as-a-service platforms by command-and-control server count, though its daily victim numbers remained relatively modest compared to other botnets of similar scale.
The research teams discovered that the malware’s success stemmed partly from its stealth capabilities, with only 25 percent of its C2 servers achieving detection scores greater than zero in VirusTotal, indicating that a significant portion of the infrastructure remained undetected by traditional security tools.
The geographic distribution of victims showed concerning patterns, with Mexico, Brazil, and the United States consistently ranking among the most impacted regions.
Despite the botnet’s global reach, the relatively targeted nature of attacks suggested that DanaBot operators were selecting fewer targets than other loaders of similar capability, likely focusing on high-value victims and timing their operations around significant events such as the November 2024 U.S. election and December holiday season.
DanaBot’s technical sophistication became evident through its implementation of a complex multi-tiered command-and-control architecture designed to obfuscate the true location of threat actors and provide resilience against takedown efforts.
The infrastructure employed a layered communications system between victims and botnet controllers, where traffic was proxied through typically two or three tiers of C2 servers before reaching the final operational tier controlled by the threat actors themselves.
When a victim became infected with DanaBot malware, their system would initiate communication with one or more Tier 1 C2 servers over TCP port 443.
These Tier 1 servers functioned as the initial point of contact, designed to appear as legitimate traffic to network monitoring systems.
Depending on the affiliate’s subscription level and access privileges, these T1 C2s would then communicate with dedicated or shared Tier 2 servers, creating an additional layer of obfuscation between the victims and the actual operators.
The Tier 2 servers maintained connections with upstream Tier 3 C2s, all of which investigators determined were located in Russia, suggesting the operation’s geographic origin.
Communication between T2 and T3 servers utilized various ports including TCP/15643 for certain cluster configurations and TCP/443 for others, indicating sophisticated traffic management and operational security practices.
This multi-tiered approach, similar to architectures employed by other prominent malware families like Emotet and Qakbot, effectively insulated the core operational infrastructure from direct exposure to security researchers and law enforcement agencies.
Equip your SOC team with deep threat analysis for faster response -> Get Extra 𝗦𝗮𝗻𝗱𝗯𝗼𝘅 𝗹𝗶𝗰𝗲𝗻𝘀𝗲𝘀 for Free
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…