We collect cookies to analyze our website traffic and performance; we never collect any personal data. Cookie Policy
Accept
NEW YORK DAWN™NEW YORK DAWN™NEW YORK DAWN™
Notification Show More
Font ResizerAa
  • Home
  • Trending
  • New York
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
  • Crypto & NFTs
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Travel
    • Fashion
    • Art
  • Health
  • Sports
  • Entertainment
Reading: DanaBot takedown reveals how agentic AI reduce months of SOC evaluation to weeks
Share
Font ResizerAa
NEW YORK DAWN™NEW YORK DAWN™
Search
  • Home
  • Trending
  • New York
  • World
  • Politics
  • Business
    • Business
    • Economy
    • Real Estate
  • Crypto & NFTs
  • Tech
  • Lifestyle
    • Lifestyle
    • Food
    • Travel
    • Fashion
    • Art
  • Health
  • Sports
  • Entertainment
Follow US
NEW YORK DAWN™ > Blog > Technology > DanaBot takedown reveals how agentic AI reduce months of SOC evaluation to weeks
DanaBot takedown reveals how agentic AI reduce months of SOC evaluation to weeks
Technology

DanaBot takedown reveals how agentic AI reduce months of SOC evaluation to weeks

Last updated: May 29, 2025 1:02 am
Editorial Board Published May 29, 2025
Share
SHARE

The latest takedown of DanaBot, a Russian malware platform chargeable for infecting over 300,000 techniques and inflicting greater than $50 million in harm, highlights how agentic AI is redefining cybersecurity operations. In keeping with a latest Lumen Applied sciences put up, DanaBot actively maintained a median of 150 lively C2 servers per day, with roughly 1,000 every day victims throughout greater than 40 nations.  

Final week, the U.S. Division of Justice unsealed a federal indictment in Los Angeles towards 16 defendants of DanaBot, a Russia-based malware-as-a-service (MaaS) operation chargeable for orchestrating huge fraud schemes, enabling ransomware assaults and inflicting tens of thousands and thousands of {dollars} in monetary losses to victims.  

DanaBot first emerged in 2018 as a banking trojan however shortly developed into a flexible cybercrime toolkit able to executing ransomware, espionage and distributed denial-of-service (DDoS) campaigns. The toolkit’s capacity to ship exact assaults on vital infrastructure has made it a favourite of state-sponsored Russian adversaries with ongoing cyber operations focusing on Ukrainian electrical energy, energy and water utilities.

DanaBot sub-botnets have been instantly linked to Russian intelligence actions, illustrating the merging boundaries between financially motivated cybercrime and state-sponsored espionage. DanaBot’s operators, SCULLY SPIDER, confronted minimal home stress from Russian authorities, reinforcing suspicions that the Kremlin both tolerated or leveraged their actions as a cyber proxy.

As illustrated within the determine under, DanaBot’s operational infrastructure concerned advanced and dynamically shifting layers of bots, proxies, loaders and C2 servers, making conventional guide evaluation impractical.

Overview of DanaBot pipeline and administration infrastructure. Supply: Crew Cymru and Lumen Applied sciences

DanaBot reveals why agentic AI is the brand new entrance line towards automated threats

Agentic AI performed a central function in dismantling DanaBot, orchestrating predictive risk modeling, real-time telemetry correlation, infrastructure evaluation and autonomous anomaly detection. These capabilities mirror years of sustained R&D and engineering funding by main cybersecurity suppliers, who’ve steadily developed from static rule-based approaches to totally autonomous protection techniques.

“DanaBot is a prolific malware-as-a-service platform in the eCrime ecosystem, and its use by Russian-nexus actors for espionage blurs the lines between Russian eCrime and state-sponsored cyber operations,” Adam Meyers, Head of Counter Adversary Operations, CrowdStrike informed VentureBeat in a latest interview. “SCULLY SPIDER operated with apparent impunity from within Russia, enabling disruptive campaigns while avoiding domestic enforcement. Takedowns like this are critical to raising the cost of operations for adversaries.”

Taking down DanaBot validated agentic AI’s worth for Safety Operations Facilities (SOC) groups by decreasing months of guide forensic evaluation into a number of weeks. All that additional time gave legislation enforcement the time they wanted to determine and dismantle DanaBot’s sprawling digital footprint shortly.

DanaBot’s takedown indicators a major shift in the usage of agentic AI in SOCs. SOC Analysts are lastly getting the instruments they should detect, analyze, and reply to threats autonomously and at scale, attaining the higher steadiness of energy within the conflict towards adversarial AI.

DanaBot takedown proves SOCs should evolve past static guidelines to agentic AI

DanaBot’s infrastructure, dissected by Lumen’s Black Lotus Labs, reveals the alarming velocity and deadly precision of adversarial AI. Working over 150 lively command-and-control servers every day, DanaBot compromised roughly 1,000 victims per day throughout greater than 40 nations, together with the U.S. and Mexico. Its stealth was placing. Solely 25% of its C2 servers registered on VirusTotal, effortlessly evading conventional defenses.

Constructed as a multi-tiered, modular botnet leased to associates, DanaBot quickly tailored and scaled, rendering static rule-based SOC defenses, together with legacy SIEMs and intrusion detection techniques, ineffective.

Cisco SVP Tom Gillis emphasised this threat clearly in a latest VentureBeat interview. “We’re talking about adversaries who continually test, rewrite and upgrade their attacks autonomously. Static defenses can’t keep pace. They become obsolete almost immediately.”

The objective is to scale back alert fatigue and speed up incident response

Agentic AI instantly addresses a long-standing problem, beginning with alert fatigue. Conventional SIEM platforms burden analysts with as much as 40% false-positive charges.

In contrast, agentic AI-driven platforms considerably scale back alert fatigue by way of automated triage, correlation and context-aware evaluation. These platforms embody: Cisco Safety Cloud, CrowdStrike Charlotte AI, Google Chronicle Safety Operations, IBM Safety QRadar Suite, Microsoft Safety Copilot, Palo Alto Networks Cortex XSIAM, SentinelOne Purple AI and Trellix Helix. Every platform leverages superior AI and risk-based prioritization to streamline analyst workflows, enabling fast identification and response to vital threats whereas minimizing false positives and irrelevant alerts.

Microsoft analysis reinforces this benefit, integrating gen AI into SOC workflows and decreasing incident decision time by practically one-third. Gartner’s projections underscore the transformative potential of agentic AI, estimating a productiveness leap of roughly 40% for SOC groups adopting AI by 2026.

“The speed of today’s cyberattacks requires security teams to rapidly analyze massive amounts of data to detect, investigate, and respond faster. Adversaries are setting records, with breakout times of just over two minutes, leaving no room for delay,” George Kurtz, president, CEO and co-founder of CrowdStrike, informed VentureBeat throughout a latest interview.

How SOC leaders are turning agentic AI into operational benefit

DanaBot’s dismantling indicators a broader shift underway: SOCs are shifting from reactive alert-chasing to intelligence-driven execution. On the middle of that shift is agentic AI. SOC leaders getting this proper aren’t shopping for into the hype. They’re taking deliberate, architecture-first approaches which might be anchored in metrics and, in lots of instances, threat and enterprise outcomes.

Key takeaways of how SOC leaders can flip agentic AI into an operational benefit embody the next:

Begin small. Scale with objective. Excessive-performing SOCs aren’t attempting to automate every little thing without delay. They’re focusing on high-volume, repetitive duties that usually embody phishing triage, malware detonation, routine log correlation and proving worth early. The consequence: measurable ROI, decreased alert fatigue, and analysts reallocated to higher-order threats.

Combine telemetry as the muse, not the end line. The objective isn’t amassing extra information, it’s making telemetry significant. Which means unifying indicators throughout endpoint, id, community, and cloud to present AI the context it wants. With out that correlation layer, even the perfect fashions under-deliver.

Set up governance earlier than scale. As agentic AI techniques tackle extra autonomous decision-making, probably the most disciplined groups are setting clear boundaries now. That features codified guidelines of engagement, outlined escalation paths and full audit trails. Human oversight isn’t a backup plan, and it’s a part of the management airplane.

Tie AI outcomes to metrics that matter. Probably the most strategic groups align their AI efforts to KPIs that resonate past the SOC: decreased false positives, sooner MTTR and improved analyst throughput. They’re not simply optimizing fashions; they’re tuning workflows to show uncooked telemetry into operational leverage.

As we speak’s adversaries function at machine velocity, and defending towards them requires techniques that may match that velocity. What made the distinction within the takedown of DanaBot wasn’t generic AI. It was agentic AI, utilized with surgical precision, embedded within the workflow, and accountable by design.

Each day insights on enterprise use instances with VB Each day

If you wish to impress your boss, VB Each day has you coated. We provide the inside scoop on what corporations are doing with generative AI, from regulatory shifts to sensible deployments, so you may share insights for max ROI.

An error occured.

GenLayer launches a brand new technique to incentivize folks to market your model utilizing AI and blockchain

You Might Also Like

Google’s Gemini transparency minimize leaves enterprise builders ‘debugging blind’

Most Soccer launches on PC and consoles as community-driven soccer sim

Studio Ulster launches $96.5M digital manufacturing facility

How Ubisoft reimagined Rainbow Six Siege X | Alex Karpazis interview

The pleasure of remodeling sand to water in Sword of the Sea | Matt Nava interview

TAGGED:agenticanalysisCutDanaBotmonthsshowsSOCtakedownweeks
Share This Article
Facebook Twitter Email Print

Follow US

Find US on Social Medias
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Popular News
A Haitian-American Artist’s Many Lenses on Life
Art

A Haitian-American Artist’s Many Lenses on Life

Editorial Board February 24, 2025
How Supergiant video games made Hades II for the Nintendo Change 2 | Greg Kasavin interview
‘Irma Vep’ Returns, More Meta Than Ever
Ai Weiwei Knocks Down the Constructing Blocks of Empire
Carrie P. Meek, 5-Term Florida Representative, Dies at 95

You Might Also Like

GenLayer launches a brand new technique to incentivize folks to market your model utilizing AI and blockchain
Technology

GenLayer launches a brand new technique to incentivize folks to market your model utilizing AI and blockchain

June 19, 2025
GenLayer launches a brand new technique to incentivize folks to market your model utilizing AI and blockchain
Technology

Saying our 2025 VB Rework Innovation Showcase finalists

June 19, 2025
OpenAI open sourced a brand new Buyer Service Agent framework — be taught extra about its rising enterprise technique
Technology

OpenAI open sourced a brand new Buyer Service Agent framework — be taught extra about its rising enterprise technique

June 19, 2025
GenLayer launches a brand new technique to incentivize folks to market your model utilizing AI and blockchain
Technology

Saying the 2025 finalists for VentureBeat Ladies in AI Awards

June 18, 2025

Categories

  • Health
  • Sports
  • Politics
  • Entertainment
  • Technology
  • World
  • Art

About US

New York Dawn is a proud and integral publication of the Enspirers News Group, embodying the values of journalistic integrity and excellence.
Company
  • About Us
  • Newsroom Policies & Standards
  • Diversity & Inclusion
  • Careers
  • Media & Community Relations
  • Accessibility Statement
Contact Us
  • Contact Us
  • Contact Customer Care
  • Advertise
  • Licensing & Syndication
  • Request a Correction
  • Contact the Newsroom
  • Send a News Tip
  • Report a Vulnerability
Term of Use
  • Digital Products Terms of Sale
  • Terms of Service
  • Privacy Policy
  • Cookie Settings
  • Submissions & Discussion Policy
  • RSS Terms of Service
  • Ad Choices
© 2024 New York Dawn. All Rights Reserved.
Welcome Back!

Sign in to your account

Lost your password?