Cyber Security News

DanaBot Malware With 150 Active C2 servers & 1,000 Daily Victims Busted in Operation Endgame

Law enforcement agencies have successfully disrupted one of the most sophisticated malware-as-a-service platforms operating in 2025, dealing a significant blow to the DanaBot botnet through Operation Endgame II.

The coordinated international effort targeted a criminal infrastructure that maintained an average of 150 active command-and-control servers daily while compromising approximately 1,000 victims across more than 40 countries.

This takedown represents one of the most comprehensive actions against cybercriminal infrastructure to date, demonstrating the effectiveness of collaborative efforts between security researchers, industry partners, and law enforcement agencies.

DanaBot first emerged in 2018 as a banking trojan designed primarily for financial credential theft, but has since evolved into a versatile and persistent threat capable of supporting a wide range of malicious activities.

Initially reported by Proofpoint researchers, the malware transformed from a simple banking trojan into a sophisticated platform used for information stealing, establishing initial access for ransomware operations, and delivering secondary payloads such as Latrodectus malware.

This evolution positioned DanaBot as a critical component in the modern cybercrime ecosystem, where threat actors increasingly rely on specialized tools for different phases of their attack campaigns.

Team Cymru analysts and researchers, working alongside Black Lotus Labs, identified the full scope of DanaBot’s infrastructure through extensive collaboration with industry peers and law enforcement agencies.

Their investigation revealed that DanaBot operated as one of the largest malware-as-a-service platforms by command-and-control server count, though its daily victim numbers remained relatively modest compared to other botnets of similar scale.

The research teams discovered that the malware’s success stemmed partly from its stealth capabilities, with only 25 percent of its C2 servers achieving detection scores greater than zero in VirusTotal, indicating that a significant portion of the infrastructure remained undetected by traditional security tools.

The geographic distribution of victims showed concerning patterns, with Mexico, Brazil, and the United States consistently ranking among the most impacted regions.

Despite the botnet’s global reach, the relatively targeted nature of attacks suggested that DanaBot operators were selecting fewer targets than other loaders of similar capability, likely focusing on high-value victims and timing their operations around significant events such as the November 2024 U.S. election and December holiday season.

Multi-Tiered Infrastructure Architecture

DanaBot’s technical sophistication became evident through its implementation of a complex multi-tiered command-and-control architecture designed to obfuscate the true location of threat actors and provide resilience against takedown efforts.

The infrastructure employed a layered communications system between victims and botnet controllers, where traffic was proxied through typically two or three tiers of C2 servers before reaching the final operational tier controlled by the threat actors themselves.

High-level diagram of multi-tiered C2 architecture (Source – TEAM CYMRU)

When a victim became infected with DanaBot malware, their system would initiate communication with one or more Tier 1 C2 servers over TCP port 443.

DanaBot pipeline and management infrastructure (Source – TEAM CYMRU)

These Tier 1 servers functioned as the initial point of contact, designed to appear as legitimate traffic to network monitoring systems.

Depending on the affiliate’s subscription level and access privileges, these T1 C2s would then communicate with dedicated or shared Tier 2 servers, creating an additional layer of obfuscation between the victims and the actual operators.

DanaBot C2-to-Tier 2 infrastructure (Source – TEAM CYMRU)

The Tier 2 servers maintained connections with upstream Tier 3 C2s, all of which investigators determined were located in Russia, suggesting the operation’s geographic origin.

DanaBot Tier 2-to-Tier 3 infrastructure (Source – TEAM CYMRU)

Communication between T2 and T3 servers utilized various ports including TCP/15643 for certain cluster configurations and TCP/443 for others, indicating sophisticated traffic management and operational security practices.

This multi-tiered approach, similar to architectures employed by other prominent malware families like Emotet and Qakbot, effectively insulated the core operational infrastructure from direct exposure to security researchers and law enforcement agencies.

Equip your SOC team with deep threat analysis for faster response -> Get Extra 𝗦𝗮𝗻𝗱𝗯𝗼𝘅 𝗹𝗶𝗰𝗲𝗻𝘀𝗲𝘀 for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago