News report
DanaBot malware is back to infecting Windows after 6-month break
BleepingComputer, November 12, 2025. Zscaler ThreatLabz's identification of DanaBot version 669 with rebuilt command-and-control on .onion domains and backconnect nodes, roughly six months after the May 2025 Operation Endgame wave..
- Source type
- News report
- Published
- November 12, 2025
- Research grade
- S2
- Used in entries
- 1
Bibliographic record
- Publisher
- BleepingComputer
- Published
- November 12, 2025
- Source type
- News report
- Research grade
- Source grade S2
- Language
- English
- Official record
- Not an official publication
- What it supports
- Zscaler ThreatLabz's identification of DanaBot version 669 with rebuilt command-and-control on .onion domains and backconnect nodes, roughly six months after the May 2025 Operation Endgame wave.
- Dataset id
- src_bleepingcomputer_danabot_return_2025
Research notes
- By Bill Toulas. JSON-LD datePublished 2025-11-12T11:34:54-05:00; page date line 'November 12, 2025'.
- Attribution of the version 669 find is to Zscaler ThreatLabz; the article also lists Bitcoin, Ethereum, Litecoin and Tron addresses tied to the new build.
How this source is used
Cited 1 time across 1 record type.
The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.
Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.
Cited by
Later activity
1 citation
Cited for activity recorded after the takedown.
-
DanaBot version 669Later outcome
Same service on replacement infrastructure, Operation Endgame wave 2