TechForge

May 26, 2025

  • The US shut down DanaBot botnet, linked to 300,000 infections and $50M in damages.
  • Sixteen people were charged, including key Russian developers.

The US Department of Justice (DoJ) has disrupted the online infrastructure behind DanaBot, a well-known malware service, and charged 16 people linked to its creation and use. The group, which US officials say is based in Russia, is accused of using DanaBot to steal data, commit fraud, and help spread ransomware around the world.

What is DanaBot?

DanaBot first appeared in 2018 in a spam campaign targeting users in Australia. Since then, it has spread globally. The malware is written in Delphi and is known for stealing personal and financial information. It has also been used to launch DDoS attacks and install other malicious software. Security firm ESET has tracked DanaBot for years and found over 1,000 unique command-and-control (C2) servers connected to its activity. Poland, Australia, and later the US and Canada have been common targets.

DanaBot has also been tied to politically motivated attacks. In 2022, for example, it was used in a DDoS attack against Ukraine’s Ministry of Defense shortly after Russia’s invasion. In a separate case, the same type of attack was directed at a Russian website focused on Arduino hardware, possibly due to personal or political motives of a DanaBot affiliate.

How the group works

The creators of DanaBot run a malware-as-a-service (MaaS) operation. This means they rent out the malware to others, known as affiliates, who use it to create and manage their own botnets. The developers even maintain a help page on the dark web explaining how the tool works.

A user known as “JimmBee” promotes the service in online forums. He’s also believed to be one of the main developers. Another figure, “Onix,” helps run the infrastructure and handles sales. According to the DoJ, both men—Aleksandr Stepanov (aka JimmBee) and Artem Kalinkin (aka Onix), from Novosibirsk, Russia—are still at large.

Authorities say DanaBot has infected more than 300,000 computers worldwide and caused over $50 million in damages. Stepanov is facing several charges, including wire fraud, identity theft, and unauthorised access to computers. Kalinkin faces charges related to computer hacking and fraud.

How they were identified

According to court documents, some of the people behind DanaBot accidentally infected their own computers with the malware. In a few cases, they may have done this on purpose to test or debug the tool. But in other cases, it seems to have been a mistake. These infections revealed personal data that helped investigators link real identities to online aliases.

If found guilty, Kalinkin could face up to 72 years in prison. Stepanov faces a maximum sentence of five years. As part of the international operation, law enforcement also took down dozens of DanaBot’s C2 servers, including many hosted in the US.

The DoJ said DanaBot typically spreads through emails containing malicious attachments or links. Once a user opens one, their device becomes part of a botnet—a network of infected computers that can be controlled remotely by cybercriminals.

DanaBot works like other MaaS platforms such as Emotet, TrickBot, QakBot, and IcedID. It’s used to steal passwords, banking details, crypto wallets, and more. It can also log keystrokes, capture video, and give remote access to attackers.

CrowdStrike noted that DanaBot started out targeting banks in Ukraine, Poland, Italy, Germany, Austria, and Australia. In late 2018, it expanded to include financial institutions in the US and Canada. The malware became popular because of its modular structure, which allowed cybercriminals to easily add features like screen recording and fake web pages to trick users.

How it operates

Research from Black Lotus Labs and Team Cymru shows DanaBot uses a multi-layered communication setup to avoid being tracked. Traffic from infected computers passes through several proxy servers before reaching its final destination. Typically, five or six proxy servers are active at any time. Most victims have been located in Brazil, Mexico, and the US.

Proofpoint data shows that DanaBot disappeared from email-based attacks between July 2020 and June 2024. During that time, criminals relied more on methods like SEO poisoning and malvertising—fake ads that trick users into downloading malware.

DanaBot’s operators also created a second version of the botnet in 2021. This one was built to spy on targets in government, diplomatic, and military sectors in North America and Europe. It could record everything happening on a victim’s computer and send the data to a separate server.

According to the DoJ, DanaBot is one of several malware services used in ways that blur the line between cybercrime and state-linked espionage. Lumen’s Black Lotus Labs told The Hacker News that DanaBot’s low-traffic control servers might suggest targeted campaigns, possibly linked to spying. However, there’s no proof confirming state sponsorship.

Law enforcement and private sector response

The DoJ credited private companies including Amazon, Google, ESET, CrowdStrike, Proofpoint, Zscaler, Intel 471, Team Cymru, Lumen, Flashpoint, Spycloud, and PayPal for helping with the investigation. These companies provided technical insight, intelligence, and access to tools that made the disruption possible.

Some of DanaBot’s sub-networks were used in state-focused attacks. Sub-botnet 5, for example, was used in the 2022 DDoS attacks on Ukraine’s Ministry of Defence and National Security and Defense Council. Sub-botnets 24 and 25 were linked to possible intelligence gathering on behalf of Russian interests.

DanaBot’s code and operations have changed often. Since 2022, operators have regularly updated the malware to avoid detection. Researchers have found at least 85 different builds. The latest version, build 4006, was compiled in March 2025. The system has several parts: the bot that infects devices, a server for managing them, a log processing tool, and a generator that creates new bots and connects them to the C2 network.

The group behind DanaBot has also worked with others in the malware business. They’ve partnered with cryptor and loader developers like Matanbuchus and offered special pricing for package deals. On average, about 150 command servers have been active each day, with around 1,000 victims daily in more than 40 countries, according to recent reports.

Another related case: QakBot

This action comes after the DoJ also brought charges against Rustam Gallyamov, a Moscow resident accused of creating and running QakBot, another major botnet. Gallyamov allegedly used QakBot to infect thousands of devices, helping ransomware groups like Black Basta and CACTUS. Authorities say Gallyamov kept operating even after the QakBot takedown in 2023 by switching to “spam bomb” attacks to access networks.

FBI officials said that even after QakBot’s shutdown, Gallyamov continued to help cybercrime groups by offering new ways to deliver malware.

Comments from the cybersecurity community

Adam Meyers, who leads CrowdStrike’s counter-adversary team, said DanaBot shows how Russian-linked cybercrime groups often operate freely while causing harm worldwide. Disruptions like this, he said, help raise the cost for attackers and slow down their work.

Selena Larson, a threat researcher at Proofpoint, called the DanaBot takedown a strong win for defenders. She said these kinds of efforts not only disrupt operations but also create fear and mistrust among cybercriminals. That may make some of them think twice before staying in the business. She also emphasised that collaboration between law enforcement and private security teams is key to taking down large botnets like this one.

Author

  • As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

    View all posts

About the Author

Muhammad Zulhusni

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

August 11, 2026

August 10, 2026

August 5, 2026

July 30, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12345 view(s)
11326 view(s)
7643 view(s)
6152 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)