DanaBot Banking Trojan Moves to Europe, Adds RDP and 64-bit Support
#1
Quote:The covert banking Trojan DanaBot uncovered by Proofpoint in May 2018 when it began targeting Australia and Poland via malicious URLs has now moved to Europe, with new e-mail campaigns affecting Italy, Austria, Germany, and Ukraine.

According to an analysis made by ESET Research, the DanaBot banking Trojan written in Delphi has a modular structure easily expandable by the threat actors behind it via plug-ins.

Before moving to Europe, during the Australian-based campaigns, DanaBot came with four plug-ins. The VNC plug-in which would allow the attacker to connect to the victim's machine, while the stealer plug-in designed to automatically collect all passwords entered in a wide range of applications.

Furthermore, DanaBot's "Australian"-flavored release came with a sniffer plug-in that would inject malicious code within the websites visited by the target to steal sensitive information such as credentials and payment data, and a TOR plug-in that helped it connect to .onion sites

Source: https://news.softpedia.com/news/danabot-...2842.shtml
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, jasonX
Reply


Messages In This Thread
DanaBot Banking Trojan Moves to Europe, Adds RDP and 64-bit Support - by silversurfer - 21 September 18, 16:11

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
uBOLite 2026.529.1448 (already available...
uBOLite 2026.529.1...harlan4096 — 08:05
Microsoft Edge 148.0.3967.96
Version 148.0.3967...harlan4096 — 08:02
Brave 1.90.128 (Chromium 148.0.7778.217)
Release v1.90.128 ...harlan4096 — 08:01
Don’t let fake IPTV apps ruin your World...
We break down how ...harlan4096 — 07:59
Microsoft Rolls Out A New Update With Lo...
Microsoft has star...harlan4096 — 07:58

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>