Cybersecurity report
Flash Report: New DanaBot Malware Variant Emerges After Takedown
ZeroFox, November 14, 2025. DanaBot's return under its own brand: a variant dubbed 'version 669' observed on 10 November 2025, six months after Operation Endgame removed 300 servers and 650 domains of the DanaBot infrastructure..
- Source type
- Cybersecurity report
- Published
- November 14, 2025
- Research grade
- T2
- Used in entries
- 1
Bibliographic record
- Publisher
- ZeroFox
- Published
- November 14, 2025
- Source type
- Cybersecurity report
- Research grade
- Source grade T2
- Language
- English
- Official record
- Not an official publication
- What it supports
- DanaBot's return under its own brand: a variant dubbed 'version 669' observed on 10 November 2025, six months after Operation Endgame removed 300 servers and 650 domains of the DanaBot infrastructure.
- Dataset id
- src_zerofox_danabot_variant_2025
Research notes
- JSON-LD datePublished 2025-11-14T19:55:26+00:00.
- ZeroFox is relaying an observation by other security researchers (footnoted); the primary identification of version 669 is Zscaler ThreatLabz's.
- Server/domain figures given here as 300 and 650 match the Endgame May 2025 wave the record describes.
How this source is used
Cited 1 time across 1 record type.
The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.
Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.
Cited by
Later activity
1 citation
Cited for activity recorded after the takedown.
-
DanaBot version 669Technical evidence
Same service on replacement infrastructure, Operation Endgame wave 2