Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
16
Global rank
14 infographic chevron month
Month rank
11 infographic chevron week
Week rank

DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.

Loader
Type
Unknown
Origin
1 July, 2019
First seen
7 October, 2026
Last seen

How to analyze DonutLoader with ANY.RUN

Type
Unknown
Origin
1 July, 2019
First seen
7 October, 2026
Last seen

IOCs

IP addresses
135.233.95.144
40.126.32.140
57.153.246.3
48.209.133.15
48.192.1.64
2.16.204.136
172.211.123.249
74.178.240.51
185.25.20.84
208.95.112.1
2.21.239.138
23.52.181.212
2.23.227.142
23.194.190.165
172.211.123.248
131.253.33.203
23.11.41.157
23.59.18.102
74.179.77.204
104.126.36.88
Hashes
2ed27c1421e6928dbe13dbfdb5c59e1045b30341fe7ebe05700006bc5ac572c0
d447a06cba8d3dbe80e09d73dd64576836b258961ee0d3ba56cf26cea7962b49
c15b04e3b90e5959057c01535d9dbb27701401ff1703d17fcfdd88f3fed6c576
448b35b90491069206a5124d74550ed91fe3882e202b4dac3e89919bb470c37e
05c1e57aa0893e4bf0823dac4853b3a92a5926e035dfcf843d9d647e051dfc9c
66fbf0c74f546fbdb32dba503afdad364228a9a4c4320924aaa310a96e7e0761
f49b515eedeed1abe391bc32f15ce43d3582cb6c41ff944fa9c79f476d5824ba
d99aaa09108e56886ab53484575db5b11f400a8a6461d32adf630935ccd4b4d9
e2c2da27bf6e2c2f8d076b9a95419a249754dc51ce6a4940c80b4af6ec9472e1
acb79df7ee7ccb16e1cc5cb55d0eaf42ab05c82311b43d5d141fd1a8613e1ff9
db0df14a9b2b7d568ebc94061b87e76fa4b50fb0ff9c9c3c5dd0de253a26ee43
4a03f7c51c537aa36d53cbae4e57e1929d549c943e3126affb046d524b1d89d8
63f55b5a66fb5d0a922f4941c8b7f0f92e0b988eb824e1fd7c65672511c6898e
c8b00e56f2ae5dc7c327f0175b94d5d8cb4b3507bf186cd8d9cb51be6af28864
0e60b52689f3627486b9a77bb4f88bea0d8665a94f7f1ffc960a1fbc427626b7
b848340aef333b6e9a65d2f2ca2f0cde08b7f7fcee661b666c9dae94643168e6
643ac89572093a4c907c1af802b3d354453c64d545dc3f1be1ce689046064511
0744da2f7421d9e81c901952ea7a214e31eac90c2752b5944b49117404966a9e
bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
d1614ad99aded9f6f5c1be7fe7ffa5124bd04a526580da3818ea8a954e852aa6
Domains
www.microsoft.com
self.events.data.microsoft.com
activation-v2.sls.microsoft.com
oneocsp.microsoft.com
nexusrules.officeapps.live.com
ocsp.digicert.com
client.wns.windows.com
ftp.artsystem.gr
fe3cr.delivery.mp.microsoft.com
crl.microsoft.com
settings-win.data.microsoft.com
ecs.office.com
www.bing.com
th.bing.com
slscr.update.microsoft.com
login.live.com
ip-api.com
google.com
ftp.enogcaen-br.com
dns.msftncsi.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
http://ip-api.com/line/?fields=hosting
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&f=9&wsbc=1
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
https://login.live.com/ppsecure/deviceaddcredential.srf
https://login.live.com/rst2.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaale%2bvmfuqbvyaaaaaaaas%3d
https://officeclient.microsoft.com/config16/?lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1024
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2815
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10289
comments 0

Inside DonutLoader: Position-Independent Malware That Leaves Almost No Trace

Key Takeaways

  1. DonutLoader enables true fileless execution by converting any payload into position-independent shellcode that runs entirely in memory.
  1. It routinely bypasses AMSI, WLDP, and static scanners through dynamic API resolution and process injection.
  1. Primary infection vectors are social-engineering tactics such as ClickFix, fake CAPTCHA pages, and obfuscated BAT/PowerShell droppers.
  1. Sectors with high-value data (defense, healthcare, logistics, finance) face elevated risk due to targeted and mass campaigns.
  1. Successful attacks often combine DonutLoader with popular RATs and stealers, leading to rapid credential theft and ransomware deployment.
  1. ANY.RUN's Threat Intelligence Lookup to instantly investigate suspicious IPs, domains, or mutexes associated with DonutLoader, see targeted sectors and gather more IOCs.

domainName:"importenptoc.com".

Domain linked to DonutLoader in TI Lookup Domain linked to DonutLoader in TI Lookup

  1. Security teams can safely detonate and fully unpack multi-stage DonutLoader chains in ANY.RUN’s Interactive Sandbox, revealing in-memory behaviors invisible to traditional tools.

View analysis

DonutLoader malware analysis in Interactive Sandbox DonutLoader fresh sample analysis in Interactive Sandbox

What is DonutLoader Malware?

DonutLoader (also tracked as Donut or donut_injector) is a powerful, open-source in-memory loader and shellcode generator that has been widely adopted by cybercriminals and advanced threat actors alike.

Originally created for legitimate red-team and penetration testing purposes, DonutLoader converts .NET assemblies, EXE files, DLL files, VBScript, and JScript payloads into position-independent shellcode that executes directly in a target system's memory, never touching the disk. This means the malicious payload lives only in memory — it never persists on the file system in an easily detectable form.

The framework supports multiple output formats, including raw shellcode binaries, as well as execution via PowerShell, Python, Ruby, JavaScript, JScript, and VBScript. This versatility makes DonutLoader highly adaptable across attack campaigns and target environments. Threat actors can generate shellcode that loads virtually any Windows payload — from commodity RATs purchased on cybercrime forums to custom espionage implants developed by state-sponsored groups.

DonutLoader also features an array of built-in anti-detection and evasion capabilities. It can patch the Windows Antimalware Scan Interface (AMSI) to prevent security tools from inspecting script content before execution. It can disable Windows Lockdown Policy (WLDP) to allow arbitrary code execution in environments that would otherwise block it. It erases in-memory references to payloads after loading to hinder forensic analysis. Furthermore, it supports encryption, compression, and obfuscation of generated code modules, making static analysis and signature-based detection extremely difficult.

Because DonutLoader is publicly available on GitHub, it has a low barrier to entry for threat actors who do not need to develop their own custom loaders. It has been integrated into the toolchains of ransomware groups, APT actors, and commodity malware operators, cementing its status as a multi-purpose weapon in the modern threat landscape. MITRE ATT&CK tracks it under the identifier S0695, and it has been associated with multiple high-profile intrusion sets.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How DonutLoader Threatens Businesses and Organizations

By operating filelessly and injecting into trusted processes, DonutLoader defeats signature-based detection and many static analysis tools, allowing initial access to go unnoticed for hours or days. Once inside, it deploys payloads that steal credentials, exfiltrate sensitive data via Discord/Telegram webhooks, establish persistence, and open the door to ransomware or espionage. The result: financial losses from data breaches, operational downtime, regulatory fines, and reputational damage. Its low footprint also complicates incident response, as traditional forensic artifacts are minimal.

Victimology: Vulnerable Industries and Sectors

DonutLoader is used globally across both mass-distribution MaaS campaigns and targeted operations, making virtually any Windows environment at risk. Sectors particularly vulnerable include:

  • Defense and government contractors — frequently targeted for espionage (e.g., Symantec and Unit42 reports).

  • Healthcare — hit by ransomware groups like CrazyHunter in Taiwan. The sector's combination of sensitive data, operational urgency, and historically limited security resources makes it extremely vulnerable to DonutLoader-enabled ransomware attacks.

  • Logistics and manufacturing — targeted in GrayBravo/CastleLoader clusters.

  • Financial Services. Evil Corp — one of the threat groups confirmed to have used DonutLoader — originally focused on banking trojans and has repeatedly targeted financial institutions. The financial sector overall experienced a 47% year-over-year increase in observed attacks in 2024, making it one of the highest-risk verticals.

  • Technology companies — particularly software vendors and managed service providers — are frequently targeted because compromising a single vendor can enable downstream attacks on hundreds of clients. DonutLoader's in-memory execution is particularly effective in environments with sophisticated endpoint monitoring, as it reduces the observable footprint of the initial infection.

How Can Businesses Proactively Protect Against DonutLoader

  • Integrate TI Feeds as the first line of proactive defense: DonutLoader campaigns constantly rotate infrastructure and update payloads. ANY.RUN’s Threat Intelligence Feeds deliver a continuous, automated stream of fresh, high-confidence DonutLoader indicators — IPs, malicious domains, URLs, — sourced directly from real-time sandbox analysis of millions of malware submissions. These feeds are provided in standard formats (STIX/TAXII, CSV, JSON) and integrate directly into SIEMs, SOAR platforms, firewalls, EDR solutions, and TIP platforms.

By automatically blocking known DonutLoader infrastructure before shellcode execution begins, and by keeping detection rules current with the latest variants, TI Feeds transform an organization’s defenses from reactive to genuinely proactive.

TI Feeds benefits and integration TI Feeds: benefits, data sources, integration options

  • Block C2 communications before payloads execute: DonutLoader often downloads staged shellcode payloads from remote C2 servers over HTTP. TI Feeds continuously surface confirmed C2 indicators associated with active DonutLoader campaigns, enabling network perimeter controls — firewalls, web proxies, DNS sinkholes — to block these connections before the payload ever reaches memory. This network-layer kill switch is particularly powerful because it operates independently of endpoint detection capabilities.

  • Deploy behavioral and memory-based endpoint detection: Traditional file-scanning tools cannot detect DonutLoader. EDR and XDR solutions that monitor process behavior, memory injection patterns, API call sequences, and anomalous process relationships are essential complements to intelligence-driven IOC blocking — catching activity that may use novel infrastructure not yet in any feed.

  • Monitor and protect AMSI: DonutLoader patches AMSI in memory to prevent script scanning. Security teams should monitor for AMSI bypass attempts and consider kernel-level protection of security interfaces as a defense-in-depth layer beyond IOC blocking.

  • Enforce network segmentation and least-privilege access: Once DonutLoader delivers a RAT or Cobalt Strike beacon, attackers rely on lateral movement to reach high-value systems. Network segmentation, micro-segmentation, and strict privileged access management limit the blast radius of any infection that TI Feed-based controls did not intercept at the perimeter.

How DonutLoader Gets in the System and Functions

Initial access is almost always via social engineering:

  • Phishing emails with malicious ZIP/LNK/BAT attachments or links to fake software updates/CAPTCHA pages.

  • Malvertising, compromised websites, or sideloaded DLLs in legitimate-looking installers.

Once executed, an obfuscated BAT or PowerShell script downloads or decrypts the Donut shellcode, which then injects the final payload. Lateral movement and further spread depend on the delivered malware (RATs often enable it via SMB, RDP, or messaging apps), but the loader itself focuses on stealthy foothold establishment rather than worm-like propagation.

Shellcode Generation

DonutLoader takes a target payload — which can be a .NET assembly, a PE executable, a DLL, a VBScript, JScript, or any of several other supported file types — and converts it into position-independent shellcode. Position-independent code (PIC) does not rely on absolute memory addresses and can execute from any location in memory, making it inherently more portable and harder to predict or block.

Encryption and Obfuscation

Generated shellcode modules are encrypted, compressed, and encoded by default. This means that even if a defender extracts the shellcode from memory, it is not immediately readable or analyzable. Each generated module can use different encryption keys and configurations, reducing the effectiveness of static signatures built on previous samples.

AMSI and WLDP Patching

Before executing its payload, DonutLoader patches the Windows Antimalware Scan Interface (AMSI) by overwriting key functions in memory to return benign results regardless of what code is executed. It similarly disables the Windows Lockdown Policy (WLDP), which is designed to restrict execution of arbitrary code. These patches occur in memory and leave no disk artifacts, making them invisible to file-based scanning tools.

Reflective Code Loading and Process Injection

DonutLoader's core mechanism is reflective code loading — the ability to load and execute a PE file or .NET assembly from memory without relying on the Windows loader or writing anything to disk. The DonutTest subproject further enables process injection, allowing the shellcode to be injected into a chosen target process rather than running in a new process that might appear suspicious.

Indicator Removal

After the payload has been reflectively loaded and started executing, DonutLoader erases its own references from memory. Post-incident memory analysis may find the payload executing but struggle to trace it back to the original loader, complicating incident response and attribution efforts.

Remote Payload Download

DonutLoader can also download previously staged shellcode payloads from remote servers over HTTP, enabling operators to host payloads externally and update them without needing to re-infect the target system. This makes DonutLoader suitable for long-term persistent access scenarios.

Sandbox Analysis of DonutLoader Sample

The processes, scripts, modules, and network connections of DonutLoader are visible in ANY.RUN’s Interactive Sandbox safe detonations:

View analysis

DonutLoader sandbox analysis DonutLoader sample in the Interactive Sandbox

The sample is an obfuscated BAT script. The first part is a script whose task is to copy the BAT file into the user’s folder.

BAT script delivering malicious file BAT script delivering malicious file in the system

The executable PowerShell command is encoded in Base64 with added garbage sequences “llifd”. This PowerShell reads the entire BAT file as raw text and searches for a predefined marker that precedes the embedded Base64 payload, decodes it, and executes it via IEX. If the file is missing or the appropriate string is not found, this block does nothing.

PowerShell command leading to payload delivery PowerShell command leading to payload delivery

Regardless of the file check, the script reads the .bat file again and searches for another marker, after which it splits the received text into 2 parts. For each of the two parts, the following operations are performed:

    1. Decodes Base64.
    1. Decrypts AES.
    1. Unpacks gzip.
    1. Compiles, loads, and executes the assemblies.

Additionally, after the PowerShell stage, the process of compiling .NET assemblies is visible.

DonutLoader processes in the Interactive Sandbox DonutLoader processes in the Interactive Sandbox

Gathering Threat Intelligence on DonutLoader Malware

ANY.RUN's Threat Intelligence Lookup provides critical capabilities for detecting, investigating, and responding to DonutLoader threats:

Rapid IOC Validation and Enrichment

SOC analysts can query TI Lookup to instantly determine if an indicator is associated with known DonutLoader campaigns. The service provides contextual information including malware family classification, campaign attribution, and related artifacts - turning isolated indicators into actionable intelligence within seconds.

Deep Behavioral Analysis Access

TI Lookup gathers direct links to interactive sandbox sessions where DonutLoader was analyzed. Analysts can observe the complete execution chain. Start exploring with the threat name lookup:

threatName:"donut".

DonutLoader sandbox analyses Fresh DonutLoader sandbox analyses found via TI Lookup

YARA Rule Development and Testing

TI Lookup's integrated YARA Search allows security teams to scan ANY.RUN's threat intelligence database with custom detection rules. Teams can develop YARA rules targeting DonutLoader unique characteristics like mutex names and immediately test them against millions of analyzed samples to validate effectiveness and minimize false positives.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

DonutLoader exemplifies the shift toward fileless, memory-resident attacks that challenge traditional defenses. Its accessibility via open-source tools and integration into MaaS ecosystems ensures it will remain a staple in the attacker toolkit. Organizations that combine strong preventive controls with behavioral detection, proactive threat intelligence, and interactive malware analysis will stay ahead of this stealthy threat.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More
Cactus Ransomware screenshot
Cactus ransomware-as-a-service (RaaS) was first caught in March 2023 targeting corporate networks. It became known for its self-encrypting payload and double extortion tactics. Cactus primarily targets large enterprises across industries in finance, manufacturing, IT, and healthcare. It is known for using custom encryption techniques, remote access tools, and penetration testing frameworks to maximize damage.
Read More
CryptoWall screenshot
CryptoWall
cryptowall
CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.
Read More
Moonrise screenshot
Moonrise
moonrise
Moonrise RAT is a newly discovered Go-based remote access trojan with zero detections at launch, featuring credential theft, keylogging, webcam access, clipboard hijacking, and UAC bypass.
Read More
NetSupport RAT screenshot
NetSupport RAT
netsupport
NetSupport RAT is a malicious adaptation of the legitimate NetSupport Manager, a remote access tool used for IT support, which cybercriminals exploit to gain unauthorized control over systems. It has gained significant traction due to its sophisticated evasion techniques, widespread distribution campaigns, and the challenge it poses to security professionals who must distinguish between legitimate and malicious uses of the underlying software.
Read More