Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 18:58:33 UTC Home > List all groups > List all tools > List all groups using tool DanaBot Tool: DanaBot Names DanaBot Category Malware Type Banking trojan, Keylogger, Credential stealer, Info stealer Description (Fortinet) It is a modular banking Trojan that has been historically linked to combining operations with other malware operators, such as those behind Gootkit. Other modules associated with DanaBot include remote desktop through VNC, information stealing, and keylogging. While it appears that this recent attack may be looking to establish a foothold in the network, the reasons behind this are currently unknown. Information Malpedia https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1e2a3277-3948-4f60-8a32-e9b9757f9330 Page 1 of 2 AlienVault OTX Last change to this tool card: 28 June 2025 Download this tool card in JSON format All groups using tool DanaBot Changed Name Country Observed Other groups   Scully Spider, TA547 [Unknown] 2017-Mar 2024   1 group listed (0 APT, 1 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1e2a3277-3948-4f60-8a32-e9b9757f9330 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1e2a3277-3948-4f60-8a32-e9b9757f9330 Page 2 of 2