DonutLoader is a shellcode-based loader built around the open-source Donut shellcode-generation framework. It packages .NET assemblies, DLLs, and native Windows executables into position-independent shellcode for in-memory execution. Although the underlying framework is a general-purpose tool, attackers widely use it as an intermediate stage to deploy backdoors, remote access trojans, and information stealers while minimizing disk-resident payload artifacts.
DonutLoader decrypts and, in applicable configurations, decompresses embedded payloads before mapping and executing them in memory. Observed configurations use Chaskey-LTS encryption and aPLib compression. Deployment chains inject Donut-generated shellcode into legitimate Windows processes and use reflective PE loading or manual mapping to execute secondary payloads. Observed shellcode also patches AMSI and ETW functions to impair inspection and telemetry. Some deployments erase PE headers and remove temporary or execution-related artifacts; these behaviors are configuration- and campaign-dependent.
Delivered payloads include QuasarRAT, Agent Tesla, Remus, PULSAR, Remcos, CASTLESTEALER, SPECTRALVIPER, and Beagle. Infection chains incorporating DonutLoader use phishing attachments, ClickFix fake-CAPTCHA lures, malicious advertising, and obfuscated script stages. Its use spans commodity cybercrime and targeted intrusions, including NGC4020 attacks against an industrial-sector organization, REF2754 intrusions against Vietnamese agribusiness and financial-services organizations, and JadeProx activity. The capabilities of these secondary payloads are distinct from DonutLoader's loading and evasion functions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On Windows systems, the hack of the Telnyx Python SDK resulted in the deployment of an executable named "msbuild.exe" that employs several obfuscation techniques to evade detection and extracts DonutLoader, a shellcode loader, from a PNG image present within the binary to load a full-featured trojan and a beacon associated with AdaptixC2, an open-source command-and-control (C2) framework.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Дешифрованные данные представляют собой шеллкод DonutLoader ... DonutLoader загружает и выполняет в памяти QuasarRAT.”
In parallel, the installer delivers PULSAR through RC4-encoded DonutLoader shellcode injected into explorer.exe.
The unsigned DLL (dbg.config) contained DONUTLOADER shellcode which it attempted to inject into sessionmsg.exe. DONUTLOADER was configured to load the SPECTRALVIPER backdoor, and ultimately the situationally-dependent P8LOADER or POWERSEAL malware families.
On Windows systems, the hack of the Telnyx Python SDK resulted in the deployment of an executable named "msbuild.exe" that employs several obfuscation techniques to evade detection and extracts DonutLoader, a shellcode loader, from a PNG image present within the binary to load a full-featured trojan and a beacon associated with AdaptixC2, an open-source command-and-control (C2) framework.
...Velvet Tempest ... used a ClickFix lure ... to drop payloads like DonutLoader and CastleRAT.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Using the recovered values, the malware establishes persistence by registering a scheduled task named IntelDriver through the Windows schtasks utility, causing execution upon user logon.
First, social engineering was employed, followed by a PowerShell dropper, and finally an in-memory infostealer payload was delivered.
The reconstructed content is subsequently Base64-decoded and decrypted using a repeating XOR key (tk) before being executed through PowerShell's Invoke-Expression (IEX) mechanism.
The infection chain begins with a heavily obfuscated Windows batch script that conceals its functionality through variable substitution and control-flow obfuscation.
Scheduled-task persistence via a VBS launcher: The malware creates a scheduled task that executes a Visual Basic Script (VBS), ensuring it automatically runs again after a system reboot or user logon.
The package is copied, marked as executable and launched in a new thread... the loader uses raw syscalls supplied by a small framework... Since all high-risk operations ... run through these handcrafted syscalls, standard API calls to monitor are never seen by common user-land EDR hooks.
It then uses DonutLoader shellcode to load the final .NET payload into memory, reducing evidence for scanners looking only for suspicious files.
This CAPTCHA instructs the user to execute a series of keyboard shortcuts (Win + R, Ctrl + V, Enter), which runs a PowerShell command previously copied to the clipboard by the website. | First, social engineering was employed... The initial point of entry is user-driven execution of a PowerShell command, delivered through a social engineering tactic known as ClickFix.
Analysis revealed multiple layers of obfuscation, including environment-variable substitution, dynamic command reconstruction, extensive control-flow flattening, and large volumes of junk REM, ECHO, and SET statements intended to hinder static analysis.
The next-stage shellcode is a payload configured from DonutLoader ... used to wrap .NET assemblies, DLLs, and EXEs into position-independent shellcode.
The loader uses self-modifying techniques with several decryption stubs to unroll itself ... [and] decrypts a 28,233-byte region ... [with] a single-byte XOR key that updates after every iteration.
Following execution notification, the malware prepares a disguised execution vehicle by creating a renamed copy of powershell.exe as HDVz.exe within the user's Downloads directory.
DONUTLOADER shellcode ... attempted to inject into sessionmsg.exe. SPECTRALVIPER can load and inject executable files.
The loader then deletes the container within seconds ... Every observed loader detonation deleted Prefetch entries and wiped %TEMP%.
After the patching has taken place, the loader decrypts a 28,233-byte region... This similar decryption routine runs three times in total.
Using the renamed ProcDump application with the -md flag, the adversary loaded dbg.config, an unsigned DLL containing malicious code.
First, the code checks the machine’s UI language and exits immediately if it detects a CIS locale, such as Russian (ru), Belarusian (by), or Kazakh (kz).
The script terminates execution when specific username and filesystem conditions are met... Systems reporting less than 3 GB of RAM are considered suspicious, causing the script to exit without further execution.
To evade detection and reduce security visibility, the malware employs process injection, dynamic Application Programming Interface (API) resolution, Antimalware Scan Interface (AMSI) bypass, Event Tracing for Windows (ETW) tampering, and memory-resident execution techniques.
the malware invokes PowerShell to query the Win32_ComputerSystem class and retrieve the total amount of installed physical memory.
IcedID post-infection C2 traffic: 94.140.114[.]40 port 443 - primsenetwolk[.]com - HTTPS traffic 94.140.114[.]40 port 443 - onyxinnov[.]lol - HTTPS traffic 158.255.211[.]126 port 443 - trashast[.]wiki - HTTPS traffic
Process Monitor captured a curl.exe process issuing an HTTP POST request to the Telegram Bot API /sendMessage endpoint.
After process injection, the .NET implant attempts to connect to 167.88.167.9:8356 via outbound TCP, suggesting a dedicated command-and-control channel.
120 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader tool; no additional behavior is specified in the content.
A loader used by the operation to deliver PULSAR payloads, including as RC4-encoded shellcode injected into explorer.exe.
A loader used in the infection chain to load the final .NET Agent Tesla payload directly into memory, helping evade file-based detection.
A loader used in the infection chain to execute the final .NET payload in memory, helping reduce on-disk artifacts and evade file-based detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.