Donut is an open-source position-independent shellcode generator and in-memory payload loader used in Windows malware execution chains. It generates shellcode capable of loading and executing .NET assemblies, native executables and DLLs, and VBScript or JScript payloads directly in memory. Donut is a reusable execution framework rather than a standalone malicious implant; the capabilities of the loaded payload are separate from those of the loader.
For .NET payloads, Donut uses the Unmanaged CLR Hosting API to initialize the Common Language Runtime, create an application domain, load an assembly, and invoke its entry point. Its payload packaging supports encryption and configurable compression. In-memory execution reduces reliance on disk-resident payloads and supports fileless infection chains. The framework also includes the DonutTest subproject, which can inject shellcode into a target process.
Donut-generated shellcode has been used to execute VenomRAT, Phemedrone Stealer, Remus Stealer, PureRAT, and PackClient. Observed delivery chains include phishing attachments, malicious shortcuts, disk-image containers, DLL sideloading, and ClickFix social engineering, with PowerShell, Python, or AutoIt components executing intermediate stages. The Chinese-speaking threat actor TA4922 used Donut Loader in tax-themed PackClient campaigns targeting organizations in India. Other observed uses include targeted spearphishing against a Russian rail freight operator and recruitment-themed attacks against cryptocurrency organizations. Its public availability and reuse across unrelated campaigns make Donut alone insufficient for actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It then uses a Donut shellcode loader to run a .NET payload in memory.
“The obtained shellcode is in fact Donut Loader ... that contains a non-obfuscated pinkman agent binary.”
The IMG disk image contained an executable and malicious DLL that leveraged DLL sideloading to execute Donut Loader and ultimately install PackClient.
The malware stands out for its heavy use of advanced defense evasion methods, including NTDLL unhooking, direct syscalls via the Bouncy Gate technique, ETW patching, and reflective loading using the Donut shellcode.
The loader decrypts an AES-wrapped payload stored on disk. The decrypted payload contains a Donut shellcode loader that embeds the final RAT and uses Chaskey block cipher as part of its payload protection scheme. Donut then decrypts the final 32-bit native RAT, maps it, and executes it in memory.
While they still leverage classic droppers like PureCrypter and Rust-based loaders running Donut shellcode, they have added a potent new tool to their arsenal: PowerLoader.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The VBScript initiates the PowerShell process and retrieves the next stage PowerShell script. The PowerShell script downloads the next stage payload from the attackers C2 server.
The downloaded installer is pre-bundled with AutoIt3.exe, which drops and loads an .au3 script from the same folder location.
apc_run_payload – the APC callback that eventually executes the decrypted shellcode... The APC callback is responsible for executing the decrypted payload in memory.
The loader first attempts deployment into the primary target process (explorer.exe)... opens the target process using OpenProcess(), allocates executable memory... writes the recovered Donut shellcode using WriteProcessMemory(), and initiates execution through CreateRemoteThread().
The embedded JavaScript loader is using an indexed string table to dynamically resolve property names.
"The Python script hands off to shellcode generated by Thewover's Donut ... a tool that wraps arbitrary executables or .NET assemblies into position-independent x86-64 shellcode."
The actor in this incident compiled the cryptominer directly on the endpoint... Silent XMR Miner Builder.exe ... executed several .NET Framework utilities and an array of C compilers.
The loader first attempts deployment into the primary target process (explorer.exe)... opens the target process using OpenProcess(), allocates executable memory... writes the recovered Donut shellcode using WriteProcessMemory(), and initiates execution through CreateRemoteThread().
The extracted shellcode is injected into the same AutoIt process.
The ne.py Python script is used for Polymorphic Asynchronous Procedure Call (APC) Injection... defaults to injecting into the explorer.exe process if no parameter is provided.
Uses the derived key and retrieved IV to decrypt the configuration, producing a Base64-encoded domain.
the user is immediately presented with a fake CAPTCHA verification instructions. The instructions trick the user into performing a specific sequence of clicks that ultimately spawn the MSHTA process and executes a malicious script.
To evade detection and reduce security visibility, the malware employs process injection, dynamic Application Programming Interface (API) resolution, Antimalware Scan Interface (AMSI) bypass, Event Tracing for Windows (ETW) tampering, and memory-resident execution techniques.
79 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
106 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offensive shellcode-generation and loading tool used to package the Remus Stealer DLL in this delivery chain. An AutoIt script decrypts the shellcode, copies it into dynamically allocated executable memory, and starts a thread at that address. The Donut-packed shellcode subsequently loads Remus Stealer within the AutoIt process.
A modified Donut loader is used within the campaign's layered infection chains to conceal final malware payloads. The article discusses it as a delivery component rather than a primary payload and does not specify which individual samples or payload families use it.
Offensive tooling used to generate position-independent code capable of enabling in-memory execution of scripts, executables, DLLs, and .NET assemblies.
A shellcode loader used in this infection chain to execute the VenomRAT .NET payload directly in memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.