Skip to main content

News report

DanaBot malware is back to infecting Windows after 6-month break

BleepingComputer, November 12, 2025. Zscaler ThreatLabz's identification of DanaBot version 669 with rebuilt command-and-control on .onion domains and backconnect nodes, roughly six months after the May 2025 Operation Endgame wave..

Source type
News report
Published
November 12, 2025
Research grade
S2
Used in entries
1

Bibliographic record

Publisher
BleepingComputer
Published
November 12, 2025
Source type
News report
Research grade
Source grade S2
Language
English
Official record
Not an official publication
What it supports
Zscaler ThreatLabz's identification of DanaBot version 669 with rebuilt command-and-control on .onion domains and backconnect nodes, roughly six months after the May 2025 Operation Endgame wave.
Dataset id
src_bleepingcomputer_danabot_return_2025

Research notes

  • By Bill Toulas. JSON-LD datePublished 2025-11-12T11:34:54-05:00; page date line 'November 12, 2025'.
  • Attribution of the version 669 find is to Zscaler ThreatLabz; the article also lists Bitcoin, Ethereum, Litecoin and Tron addresses tied to the new build.

How this source is used

Cited 1 time across 1 record type.

The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.

Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.

Cited by

Later activity

1 citation

Cited for activity recorded after the takedown.

  • DanaBot version 669

    Same service on replacement infrastructure, Operation Endgame wave 2

    Later outcome