Monday, March 3, 2025
HomeComputer SecurityDanaBot Banking Trojan Evolves Again - Steals Email Address From Victim's Mailbox

DanaBot Banking Trojan Evolves Again – Steals Email Address From Victim’s Mailbox

Published on

SIEM as a Service

Follow Us on Google News

DanaBot Banking Trojan came out with new features which harvest email addresses from the victim’s mailbox and send out spam emails.

This Trojan turned out to be the latest example for the malware which focused on stealing useful information rather than demanding ransom from victims. The campaign primarily focuses on corporate and public administration emails.

DanaBot Banking Trojan Gets into Email Spam

In September 2018, ESET researchers noticed that the trojan used web injections against users of an unnamed Italian mail service.

An investigation has shown that malicious javascript embedded in the pages of webmail services fall into two categories.

First, DanaBot collects email addresses from the victim’s existing mailboxes and sends all the collected information to the C&C server.

Secondly, if the mail service is based on Open-Xchange, the Trojan injects a Javascript that covertly sends spam from the victim mailbox.

The mail attachment includes ZIP file which contains a decoy PDF document and a malicious VBS file, Once the VBS file executes, it downloads more malware using PowerShell cmd.

Code creating an email and adding a malicious ZIP attachment

This trojan includes a significant amount of junk code including instructions, conditional statements, and loops.

To prevent researchers and automated tools from easily understanding the code’s purpose, the trojan uses Windows API function hashing and encrypted strings.

ESET Researchers found that the links between DanaBot and GootKit. Matches were also noticed in the subnet of C&C servers and the strange similarity of domains used by the attacker.

Researchers said DanaBot uses exactly the same scripts that used in BackSwap trojan including the namings and locations of scripts in the server.

Check out the details about targeted webmail services, list of active C&C servers, targeted domains, IoCs which were shared by ESET.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Latest articles

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Hackers Using PowerShell and Microsoft Legitimate Apps to Deploy Malware

Cybersecurity experts are warning of an increasing trend in fileless attacks, where hackers leverage...

JavaGhost: Exploiting Amazon IAM Permissions for Phishing Attacks

Unit 42 researchers have observed a threat actor group known as JavaGhost exploiting misconfigurations...

New Poco RAT Via Weaponized PDF Attacking Users to Capture Sensitive Data

A new variant of malware, dubbed "Poco RAT," has emerged as a potent espionage...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Hackers Using PowerShell and Microsoft Legitimate Apps to Deploy Malware

Cybersecurity experts are warning of an increasing trend in fileless attacks, where hackers leverage...

JavaGhost: Exploiting Amazon IAM Permissions for Phishing Attacks

Unit 42 researchers have observed a threat actor group known as JavaGhost exploiting misconfigurations...