Skip to main content

Cybersecurity report

Flash Report: New DanaBot Malware Variant Emerges After Takedown

ZeroFox, November 14, 2025. DanaBot's return under its own brand: a variant dubbed 'version 669' observed on 10 November 2025, six months after Operation Endgame removed 300 servers and 650 domains of the DanaBot infrastructure..

Source type
Cybersecurity report
Published
November 14, 2025
Research grade
T2
Used in entries
1

Bibliographic record

Publisher
ZeroFox
Published
November 14, 2025
Source type
Cybersecurity report
Research grade
Source grade T2
Language
English
Official record
Not an official publication
What it supports
DanaBot's return under its own brand: a variant dubbed 'version 669' observed on 10 November 2025, six months after Operation Endgame removed 300 servers and 650 domains of the DanaBot infrastructure.
Dataset id
src_zerofox_danabot_variant_2025

Research notes

  • JSON-LD datePublished 2025-11-14T19:55:26+00:00.
  • ZeroFox is relaying an observation by other security researchers (footnoted); the primary identification of version 669 is Zscaler ThreatLabz's.
  • Server/domain figures given here as 300 and 650 match the Endgame May 2025 wave the record describes.

How this source is used

Cited 1 time across 1 record type.

The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.

Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.

Cited by

Later activity

1 citation

Cited for activity recorded after the takedown.

  • DanaBot version 669

    Same service on replacement infrastructure, Operation Endgame wave 2

    Technical evidence