Botnet
DanaBot
aka DanaTools
Proofpoints describes DanaBot as the latest example of malware focused on persistence and stealing useful information that can later be monetized rather than demanding an immediate ransom from victims.
DanaBot, also known as DanaTools, is a Windows botnet operated by SCULLY SPIDER.
Background
Proofpoint characterizes DanaBot as part of a trend toward malware that prioritizes persistence and the theft of monetizable information over demanding immediate ransom payments. The low-volume DanaBot campaigns observed have used carefully crafted social engineering, reflecting a renewed emphasis on "quality over quantity" in email-borne threats. Because the banker is modular, it can pull down extra components on demand, broadening its data-theft and remote-monitoring functionality.
Source: Malpedia (Fraunhofer FKIE).