Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The May 2025 DanaBot operation disrupted a criminal malware-for-hire platform that U.S. investigators say infected more than 300,000 computers and caused at least $50 million in damage. Authorities seized U.S.-hosted command infrastructure and charged 16 alleged participants, but two named Russian defendants were still believed to be in Russia and not in custody when the charges were announced. The operation was a significant disruption, not proof that every infection was removed or that the threat was permanently ended.

What was DanaBot?

DanaBot was a malware-as-a-service operation: its operators allegedly maintained the malware and supporting tools, then rented access to affiliates who used it against their own targets. It was more than a one-off virus or a single campaign. According to Dark Reading’s May 27, 2025 analysis, the malware was first identified in 2018 as an infostealer and banking Trojan, then developed into a broader criminal platform.

The U.S. Department of Justice (DOJ) said administrators typically charged affiliates several thousand dollars per month for access and support tools. Dark Reading reported that affiliates could choose rental options and distribute their own builds, while the authors provided an administration panel, a back-connect tool and a proxy application.

How did DanaBot infect computers and what could it do?

Delivery and botnet access

According to the DOJ, spam emails carrying malicious attachments or hyperlinks were used to infect computers. An infected device could then join a botnet that operators controlled remotely. Renting access let affiliates use that infrastructure without having to build and maintain the whole operation themselves.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Data theft and remote control

The DOJ described DanaBot as capable of stealing stored credentials, browsing histories, banking-session information, device details, cryptocurrency-wallet data and other files. Its functions also included keylogging, video recording and remote access to compromised machines. Affiliates could use those capabilities to steal information or to gain an initial foothold from which to deliver ransomware.

Victims and scale alleged by prosecutors

The DOJ attributed more than 300,000 infected computers worldwide and at least $50 million in damage to the scheme. It also said a second variant targeted military, diplomatic, law-enforcement and other government-related systems in North America and Europe. These are figures and allegations reported by prosecutors, not a post-takedown count of active infections.

Was DanaBot used by Russian intelligence?

There are two distinct claims to keep separate: DanaBot was a criminal service, and researchers have reported espionage-focused use with Russian-intelligence ties. Dark Reading reported that CrowdStrike and ESET identified DanaBot sub-botnets used for espionage and linked to Russian intelligence. Their reporting also described alleged attacks supporting Russia’s invasion of Ukraine, including a DDoS attack against Ukraine’s Ministry of Defense.

Those intelligence links are attributed to CrowdStrike and ESET; they are not findings established by the DOJ indictment described here. The reporting argues that Russian tolerance of, or use of, criminal proxies can blur the boundary between cybercrime and state-sponsored activity. It does not establish that the criminal operators and the Russian government were the same entity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did the May 2025 takedown accomplish?

Infrastructure disruption and victim assistance

On May 22, 2025, the DOJ announced charges against 16 defendants allegedly tied to DanaBot. The Defense Criminal Investigative Service seized U.S.-based command-and-control infrastructure, including dozens of virtual servers hosted in the United States. CrowdStrike, as quoted in Dark Reading’s May 27 analysis, said the seizure effectively neutralized the threat actor’s ability to issue commands to compromised systems.

The operation also had a victim-response component: the DOJ said Shadowserver and partners worked to notify victims and help remediate infections. Operation Endgame provided international coordination. Investigative partners included Germany’s Federal Criminal Police Office (BKA), the Netherlands National Police and the Australian Federal Police. Private-sector assistance came from Amazon, CrowdStrike, ESET, Flashpoint, Google, Intel 471, Lumen, PayPal, Proofpoint, SpyCloud, Team Cymru and Zscaler.

Why the seizure is not the same as a final end

Taking control of identified command infrastructure can disrupt a botnet’s operators, but it does not by itself demonstrate that every infected computer has been cleaned, that no other infrastructure exists or that all participants have been arrested. The DOJ announcement did not establish a post-takedown infection count.

The two named Russian defendants, Aleksandr Stepanov, also known as “JimmBee,” and Artem Aleksandrovich Kalinkin, also known as “Onix,” were believed to be in Russia and were not in custody when the DOJ published its release. The charges remain allegations, and all defendants are presumed innocent unless proven guilty. The DOJ listed statutory maximum penalties of up to 72 years for Kalinkin and five years for Stepanov if convicted; these are potential legal maximums, not sentences imposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you do if you think DanaBot infected your PC?

If there are signs of compromise, prioritize containment and account security rather than assuming that the takedown cleaned the computer. For a work device, contact your organization’s IT or security team immediately and follow its incident-response process.

  1. Disconnect the suspected device from networks. If practical, turn off Wi-Fi and unplug Ethernet to limit remote access and further communication. Avoid using the device to sign in to sensitive accounts.
  2. Use a separate, known-clean device to secure accounts. Change passwords for accounts that may have been accessed, starting with email, banking and cryptocurrency services. Revoke active sessions where the service allows it, and enable phishing-resistant multifactor authentication when available.
  3. Get a security assessment before returning the device to use. Run current endpoint protection or seek professional incident-response help, especially if financial, work or government information may be involved. Preserve relevant evidence if an organization or investigator needs it.
  4. Patch and monitor after remediation. Apply operating-system and application updates, review account and financial activity for unauthorized access, and watch for further alerts or suspicious sign-ins.

What the takedown means for Russian cybercrime

The operation shows how coordinated law-enforcement and private-sector work can remove important infrastructure from a large criminal service and help victims respond. It also illustrates the limits of infrastructure seizures: the criminal network’s alleged leaders were not in custody, victim cleanup is separate from server seizure, and reported espionage use does not make every DanaBot infection a state operation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.