The U.S. Department of Justice (DoJ) announced the takedown of the DanaBot malware infrastructure and unsealed indictments against 16 individuals accused of fueling a global malware-as-a-service (MaaS) operation that caused over $50 million in damages. The sophisticated cyber scheme, allegedly operated by a Russia-based group, infected more than 300,000 devices worldwide.
Aleksandr Stepanov, 39, and Artem Kalinkin, 34, both from Novosibirsk, Russia, were charged who remain at large. Stepanov faces multiple counts, including conspiracy, wire fraud, aggravated identity theft, and unauthorized computer access. Kalinkin is charged with conspiracy to commit computer fraud and unauthorized system impairment.
Court documents reveal that some defendants inadvertently infected their own devices while testing or deploying the malware, unintentionally exposing their real identities. “One of the hazards of committing cybercrime is that criminals will sometimes infect themselves with their own malware by mistake,” the DoJ noted.
Operation Endgame Hits DanaBot Infrastructure
This operation, codenamed Operation Endgame, resulted in the seizure of DanaBot’s command-and-control (C2) servers, including dozens hosted in the United States. The malware infiltrated systems via spam emails containing malicious links or attachments. Once infected, victims’ computers became part of a botnet, giving remote operators full control over their systems.
DanaBot, active since 2018, evolved from a banking trojan into a modular MaaS platform capable of stealing credentials, hijacking banking sessions, logging keystrokes, capturing video, and even facilitating ransomware attacks. It was offered to cybercriminal affiliates for fees ranging from $500 to several thousand dollars per month.
Security firm CrowdStrike highlighted DanaBot’s growth due to its early adoption of modular architecture and Zeus-based web injects. The malware initially targeted countries like Ukraine, Poland, and Australia before shifting focus to the U.S. and Canada in late 2018.
DanaBot’s Espionage Reach and Military Targeting
More recently, DanaBot deployed advanced versions to target sensitive entities in North America and Europe, including military and diplomatic organizations. A version released in January 2021 could record all activity on infected devices and send it to dedicated espionage servers.
Key findings include:
- DanaBot sub-botnets 24 and 25 were used for espionage linked to Russian government interests.
- Sub-botnet 5 was employed in DDoS attacks against Ukrainian defense infrastructure in March 2022.
- The malware’s infrastructure maintained around 150 tier-1 C2 servers daily, with victims in more than 40 countries.
- At least 85 different build versions of DanaBot have been identified, the latest compiled in March 2025.
Researchers from Black Lotus Labs and Team Cymru described DanaBot’s layered C2 architecture, which obfuscated tracking efforts. Victims were primarily located in Brazil, Mexico, and the U.S.
Wider Crackdown on Cybercrime
The DoJ credited private sector collaboration as crucial to the operation’s success. Partners included Amazon, CrowdStrike, ESET, Flashpoint, Google, Intel 471, Lumen, PayPal, Proofpoint, Spycloud, Team Cymru, and Zscaler.
“This is a victory for defenders,” said Proofpoint threat researcher Selena Larson. “Disruptions like this force cybercriminals to alter their tactics and shake trust in the criminal ecosystem.”
In a related move, the DoJ unsealed charges against Rustam Gallyamov, a 48-year-old Moscow resident and alleged architect of the QakBot malware. QakBot was dismantled in 2023, but Gallyamov and his associates reportedly shifted tactics, conducting spam bomb attacks and deploying ransomware like Black Basta and CACTUS as recently as January 2025.
Authorities also filed a civil forfeiture case for over $24 million in cryptocurrency tied to Gallyamov.
“Even after the QakBot takedown, Gallyamov brazenly adapted, proving the resilience of these criminal enterprises,” said FBI Assistant Director Akil Davis.
The takedown of DanaBot and charges against QakBot’s operator reflect a growing global effort to disrupt major cybercrime operations. As law enforcement and tech companies strengthen cooperation, cybercriminals may find it harder to operate with impunity in an increasingly hostile digital environment.

















Comments