DanaBot Resurfaces After Six-Month Hiatus Despite Major Takedown Operation
467/68 Friday, November 14, 2025 Researchers have detected new DanaBot activity, marking the return of the malware after it was dismantled during the large-scale international Operation Endgame in May. The newly observed variant features a rebuilt command-and-control (C2) infrastructure using Tor-based (.onion) domains and backconnect nodes to remotely control infected devices. Investigators also identified several […]
