By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
PulseReporterPulseReporter
  • Home
  • Entertainment
  • Lifestyle
  • Money
  • Tech
  • Travel
  • Investigations
Reading: Agentic AI defeated DanaBot, exposing key classes for SOC groups
Share
Notification Show More
Font ResizerAa
PulseReporterPulseReporter
Font ResizerAa
  • Home
  • Entertainment
  • Lifestyle
  • Money
  • Tech
  • Travel
  • Investigations
Have an existing account? Sign In
Follow US
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
PulseReporter > Blog > Tech > Agentic AI defeated DanaBot, exposing key classes for SOC groups
Tech

Agentic AI defeated DanaBot, exposing key classes for SOC groups

Pulse Reporter
Last updated: May 29, 2025 1:50 am
Pulse Reporter 3 days ago
Share
Agentic AI defeated DanaBot, exposing key classes for SOC groups
SHARE

Be part of our each day and weekly newsletters for the most recent updates and unique content material on industry-leading AI protection. Study Extra


The latest takedown of DanaBot, a Russian malware platform answerable for infecting over 300,000 techniques and inflicting greater than $50 million in injury, highlights how agentic AI is redefining cybersecurity operations. In keeping with a latest Lumen Applied sciences publish, DanaBot actively maintained a median of 150 lively C2 servers per day, with roughly 1,000 each day victims throughout greater than 40 nations.  

Final week, the U.S. Division of Justice unsealed a federal indictment in Los Angeles towards 16 defendants of DanaBot, a Russia-based malware-as-a-service (MaaS) operation answerable for orchestrating huge fraud schemes, enabling ransomware assaults and inflicting tens of hundreds of thousands of {dollars} in monetary losses to victims.  

DanaBot first emerged in 2018 as a banking trojan however shortly developed into a flexible cybercrime toolkit able to executing ransomware, espionage and distributed denial-of-service (DDoS) campaigns. The toolkit’s capability to ship exact assaults on crucial infrastructure has made it a favourite of state-sponsored Russian adversaries with ongoing cyber operations concentrating on Ukrainian electrical energy, energy and water utilities.

DanaBot sub-botnets have been immediately linked to Russian intelligence actions, illustrating the merging boundaries between financially motivated cybercrime and state-sponsored espionage. DanaBot’s operators, SCULLY SPIDER, confronted minimal home stress from Russian authorities, reinforcing suspicions that the Kremlin both tolerated or leveraged their actions as a cyber proxy.

As illustrated within the determine under, DanaBot’s operational infrastructure concerned complicated and dynamically shifting layers of bots, proxies, loaders and C2 servers, making conventional handbook evaluation impractical.

Overview of DanaBot pipeline and administration infrastructure. Supply: Crew Cymru and Lumen Applied sciences

DanaBot exhibits why agentic AI is the brand new entrance line towards automated threats

Agentic AI performed a central function in dismantling DanaBot, orchestrating predictive risk modeling, real-time telemetry correlation, infrastructure evaluation and autonomous anomaly detection. These capabilities mirror years of sustained R&D and engineering funding by main cybersecurity suppliers, who’ve steadily developed from static rule-based approaches to totally autonomous protection techniques.

“DanaBot is a prolific malware-as-a-service platform within the eCrime ecosystem, and its use by Russian-nexus actors for espionage blurs the traces between Russian eCrime and state-sponsored cyber operations,” Adam Meyers, Head of Counter Adversary Operations, CrowdStrike informed VentureBeat in a latest interview. “SCULLY SPIDER operated with obvious impunity from inside Russia, enabling disruptive campaigns whereas avoiding home enforcement. Takedowns like this are crucial to elevating the price of operations for adversaries.”

Taking down DanaBot validated agentic AI’s worth for Safety Operations Facilities (SOC) groups by decreasing months of handbook forensic evaluation into a number of weeks. All that additional time gave legislation enforcement the time they wanted to determine and dismantle DanaBot’s sprawling digital footprint shortly.

DanaBot’s takedown alerts a big shift in using agentic AI in SOCs. SOC Analysts are lastly getting the instruments they should detect, analyze, and reply to threats autonomously and at scale, attaining the higher steadiness of energy within the struggle towards adversarial AI.

DanaBot takedown proves SOCs should evolve past static guidelines to agentic AI

DanaBot’s infrastructure, dissected by Lumen’s Black Lotus Labs, reveals the alarming pace and deadly precision of adversarial AI. Working over 150 lively command-and-control servers each day, DanaBot compromised roughly 1,000 victims per day throughout greater than 40 nations, together with the U.S. and Mexico. Its stealth was placing. Solely 25% of its C2 servers registered on VirusTotal, effortlessly evading conventional defenses.

Constructed as a multi-tiered, modular botnet leased to associates, DanaBot quickly tailored and scaled, rendering static rule-based SOC defenses, together with legacy SIEMs and intrusion detection techniques, ineffective.

Cisco SVP Tom Gillis emphasised this danger clearly in a latest VentureBeat interview. “We’re speaking about adversaries who frequently check, rewrite and improve their assaults autonomously. Static defenses can’t maintain tempo. They grow to be out of date virtually instantly.”

The objective is to cut back alert fatigue and speed up incident response

Agentic AI immediately addresses a long-standing problem, beginning with alert fatigue. Conventional SIEM platforms burden analysts with as much as 40% false-positive charges.

Against this, agentic AI-driven platforms considerably cut back alert fatigue by means of automated triage, correlation and context-aware evaluation. These platforms embody: Cisco Safety Cloud, CrowdStrike Charlotte AI, Google Chronicle Safety Operations, IBM Safety QRadar Suite, Microsoft Safety Copilot, Palo Alto Networks Cortex XSIAM, SentinelOne Purple AI and Trellix Helix. Every platform leverages superior AI and risk-based prioritization to streamline analyst workflows, enabling fast identification and response to crucial threats whereas minimizing false positives and irrelevant alerts.

Microsoft analysis reinforces this benefit, integrating gen AI into SOC workflows and decreasing incident decision time by practically one-third. Gartner’s projections underscore the transformative potential of agentic AI, estimating a productiveness leap of roughly 40% for SOC groups adopting AI by 2026.

“The pace of right now’s cyberattacks requires safety groups to quickly analyze huge quantities of knowledge to detect, examine, and reply sooner. Adversaries are setting data, with breakout instances of simply over two minutes, leaving no room for delay,” George Kurtz, president, CEO and co-founder of CrowdStrike, informed VentureBeat throughout a latest interview.

How SOC leaders are turning agentic AI into operational benefit

DanaBot’s dismantling alerts a broader shift underway: SOCs are transferring from reactive alert-chasing to intelligence-driven execution. On the heart of that shift is agentic AI. SOC leaders getting this proper aren’t shopping for into the hype. They’re taking deliberate, architecture-first approaches which can be anchored in metrics and, in lots of instances, danger and enterprise outcomes.

Key takeaways of how SOC leaders can flip agentic AI into an operational benefit embody the next:

Begin small. Scale with goal. Excessive-performing SOCs aren’t attempting to automate all the pieces directly. They’re concentrating on high-volume, repetitive duties that usually embody phishing triage, malware detonation, routine log correlation and proving worth early. The outcome: measurable ROI, lowered alert fatigue, and analysts reallocated to higher-order threats.

Combine telemetry as the inspiration, not the end line. The objective isn’t amassing extra knowledge, it’s making telemetry significant. Meaning unifying alerts throughout endpoint, id, community, and cloud to offer AI the context it wants. With out that correlation layer, even the most effective fashions under-deliver.

Set up governance earlier than scale. As agentic AI techniques tackle extra autonomous decision-making, essentially the most disciplined groups are setting clear boundaries now. That features codified guidelines of engagement, outlined escalation paths and full audit trails. Human oversight isn’t a backup plan, and it’s a part of the management airplane.

Tie AI outcomes to metrics that matter. Essentially the most strategic groups align their AI efforts to KPIs that resonate past the SOC: lowered false positives, sooner MTTR and improved analyst throughput. They’re not simply optimizing fashions; they’re tuning workflows to show uncooked telemetry into operational leverage.

Right now’s adversaries function at machine pace, and defending towards them requires techniques that may match that velocity. What made the distinction within the takedown of DanaBot wasn’t generic AI. It was agentic AI, utilized with surgical precision, embedded within the workflow, and accountable by design.

Every day insights on enterprise use instances with VB Every day

If you wish to impress your boss, VB Every day has you lined. We provide the inside scoop on what firms are doing with generative AI, from regulatory shifts to sensible deployments, so you may share insights for optimum ROI.

Learn our Privateness Coverage

Thanks for subscribing. Try extra VB newsletters right here.

An error occured.


You Might Also Like

The Verge’s information to Black Friday 2024

The Beats Match Professional, our favourite fitness-centric earbuds, are matching their finest value

Wordle at the moment: The reply and hints for Could 17, 2025

The 11 Most WIRED Watches That Dropped at Watches & Wonders 2025

OpenAI unveils experimental ‘Swarm’ framework, igniting debate on AI-driven automation

Share This Article
Facebook Twitter Email Print
Previous Article Here is how you can pack the proper wardrobe on your subsequent cruise Here is how you can pack the proper wardrobe on your subsequent cruise
Next Article Folks Are Calling Out The Most Ridiculous Tropes That TV Exhibits And Films Maintain Displaying That Simply Aren't How Folks Really Stay Folks Are Calling Out The Most Ridiculous Tropes That TV Exhibits And Films Maintain Displaying That Simply Aren't How Folks Really Stay
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

More News

The 8 Finest Handheld Vacuums, Examined and Reviewed (2025)
The 8 Finest Handheld Vacuums, Examined and Reviewed (2025)
7 minutes ago
OPEC+ agrees on third oil provide surge regardless of Russia’s qualms
OPEC+ agrees on third oil provide surge regardless of Russia’s qualms
12 minutes ago
Common Love Tune Revealed As Creepy Stalker Anthem
Common Love Tune Revealed As Creepy Stalker Anthem
49 minutes ago
Twitch updates: Vertical video and twin streaming
Twitch updates: Vertical video and twin streaming
1 hour ago
Individuals Who Have Been To Celeb-Owned Eating places Are Sharing What The Expertise Is Actually Like
Individuals Who Have Been To Celeb-Owned Eating places Are Sharing What The Expertise Is Actually Like
2 hours ago

About Us

about us

PulseReporter connects with and influences 20 million readers globally, establishing us as the leading destination for cutting-edge insights in entertainment, lifestyle, money, tech, travel, and investigative journalism.

Categories

  • Entertainment
  • Investigations
  • Lifestyle
  • Money
  • Tech
  • Travel

Trending

  • The 8 Finest Handheld Vacuums, Examined and Reviewed (2025)
  • OPEC+ agrees on third oil provide surge regardless of Russia’s qualms
  • Common Love Tune Revealed As Creepy Stalker Anthem

Quick Links

  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Disclaimer
2024 © Pulse Reporter. All Rights Reserved.
Welcome Back!

Sign in to your account