Danabot Malware Reemerges with Version 669 After Operation Endgame
The notorious Danabot banking malware has made a comeback with the release of version 669, marking a significant return after nearly six months of silence following the coordinated law enforcement takedown known as Operation Endgame in May 2025.The…
The notorious Danabot banking malware has made a comeback with the release of version 669, marking a significant return after nearly six months of silence following the coordinated law enforcement takedown known as Operation Endgame in May 2025.The resurgence signals that cybercriminals behind the malware have successfully regrouped and reestablished their command-and-control (C2) infrastructure despite international law enforcement efforts to dismantle the threat.Operation Endgame, executed in May 2025, represented a significant coordinated international law enforcement action targeting multiple botnets and cybercriminal operations.While the operation temporarily disrupted Danabot’s operations, threat actors have now demonstrated their resilience by rebuilding their malware and launching a new campaign with version 669.This nearly six-month hiatus suggests a strategic regrouping period, during which operators likely worked to reestablish C2 infrastructure and update their malware codebase to evade detection mechanisms deployed after the takedown.Command-and-Control InfrastructureSecurity researchers have identified multiple newly deployed C2 servers, indicating that the threat actors have significantly diversified their infrastructure strategy.The discovered C2 endpoints include both traditional IP-based servers and Tor-hosted domains, demonstrating a hybrid approach designed to improve persistence and evade network-based takedowns.The identified C2 servers are located at 62.60.226[.]146:443, 62.60.226[.]154:443, and 80.64.19[.]39:443 for direct connections.Additionally, the operators have deployed Tor-based C2 infrastructure using hidden service domains to maintain anonymity and increase resilience against future law enforcement actions.The malware also utilizes backconnect C2 servers at 158.94.208[.]102 on ports 443 and 8080, which likely facilitate reverse shell connections and enable operators to maintain persistent access to compromised systems.Danabot version 669 continues to focus on cryptocurrency theft, a highly lucrative attack vector that has become increasingly common among banking malware families.The resurfaced variant is currently configured to target multiple blockchain networks and digital assets, utilizing dedicated wallet addresses for each supported cryptocurrency.The identified theft wallet addresses include a Bitcoin address (12eTGpL8EqYowAfw7DdqmeiZ87R922wt5L), an Ethereum address (0xb49a8bad358c0adb639f43c035b8c06777487dd7), a Litecoin address (LedxKBWF4MiM3x9F7zmCdaxnnu8A8SUohZ), and a TRON address (TY4iNhGut31cMbE3M6TU5CoCXvFJ5nP59i). This multi-currency approach maximizes the threat actors’ ability to monetize compromised systems regardless of which cryptocurrencies victims may hold.Implications for OrganizationsThe resurgence of Danabot version 669 underscores the persistent threat posed by sophisticated banking malware families and the limitations of one-off law enforcement operations in permanently eliminating cybercriminal infrastructure.Organizations must remain vigilant against this threat through robust endpoint detection and response (EDR) solutions, network monitoring for the identified C2 infrastructure, and security awareness training for employees.Financial institutions and cryptocurrency exchanges should implement enhanced monitoring for suspicious transaction activity associated with the identified wallet addresses and consider implementing behavioral analysis to detect Danabot’s characteristic command injection and credential theft activities.The reemergence of Danabot demonstrates that threat actors operating sophisticated malware families continue to adapt, rebuild, and deploy new campaigns despite significant law enforcement intervention.Continued monitoring and information sharing among cybersecurity professionals remains critical to tracking and mitigating this evolving threat.Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Based on reporting by GBHackers.
