Malware
Danabot
- First Reported
- May 19, 2026
- Latest Reported
- May 19, 2026
Reported Context (1)
- contain a PowerShell script downloaded and executed in memory. These IPs are typically used by XWorm/Danabot. PowerShell keywords are split into multiple tokens to bypass detection. Bitdefender Details Malware Campaigns Abusing Windows’ MSHTA Utility
Malware (9)
People (1)
MITRE ATT&CK (10)
Vendors (2)
Products (7)
Tools (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.