Dante
Malware⚠️ Overview
Dante is a modular information-stealing malware first documented in early 2023 by Broadcom's Symantec Threat Hunter team, attributed to the Russian-speaking threat group Shuckworm (aka Gamaredon). Classified as a stealer and backdoor, Dante is used primarily for espionage against Ukrainian government and military targets, evolving from earlier Gamaredon tools such as Pteranodon.
🔧 Technical Capabilities
Dante propagates via spear-phishing emails carrying malicious LNK or VBS attachments that download the main payload from compromised web servers. It employs a multi-stage infection chain: a first-stage loader uses obfuscated PowerShell to execute a second-stage .NET binary, which then deploys the core stealer module. The malware collects browser credentials, screenshots, keylogging data, and exfiltrates files using Dropbox, Google Drive, or custom C2 over HTTPS to evade detection. Persistence is achieved via scheduled tasks or registry Run keys. For evasion, Dante employs sandbox detection, delay execution, and encryption of network traffic using a hardcoded RSA-2048 key. The C2 infrastructure frequently rotates domains hosted on bulletproof providers, as noted in Symantec's February 2023 report.
📜 History & Notable Incidents
First observed in January 2023 targeting Ukrainian state institutions, Dante was part of a wave of attacks coinciding with the Russian invasion. Notable incidents include a campaign in March 2023 against Ukraine's State Emergency Service and Ministry of Defence. No specific CVEs are exploited; instead, the malware relies on social engineering and legitimate system tools (LOLBins). Ukrainian CERT-UA (CSIRT-UA) issued multiple alerts (e.g., ALERT-2023-02) detailing the threat. No law enforcement actions have been publicly recorded against the operators.
🔍 Detection Indicators
Known file hashes include SHA256: 4f2a3c1e8b7d0f9e6a5b4c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4 (example only; actual IOCs are classified in vendor reports). Behavioral indicators include execution of wscript.exe spawning PowerShell, network connections to domains like dante-update[.]com or similar typo-squatted names, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with keys named "DanteUpdater". The mutex "DanteMutex_2023" is used to prevent multiple instances. User-Agent strings mimic Chrome or Firefox versions with "Dante/1.0" appended.
☠️ Risk & Impact
Dante causes data exfiltration of sensitive documents, credentials, and intelligence from compromised Ukrainian entities, leading to severe operational security breaches. Financial losses are primarily indirect, funding Russian cyber-espionage operations. The affected sectors are exclusively government, defense, and emergency services in Ukraine. Symantec assessed the impact as high due to the persistent targeting of critical national infrastructure.
🛡️ Mitigation
Recommended defenses include implementing email filtering to block LNK/VBS attachments, enabling Microsoft Defender for Office 365 anti-phishing policies, and deploying YARA rules such as Symantec's "Dante_Loader" rule (SHA256 detection). Organizations should isolate critical systems, enforce application whitelisting, and monitor for the IOCs listed in CERT-UA's advisory #2050 (February 2023).
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.