Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
18
Global rank
14 infographic chevron month
Month rank
17 infographic chevron week
Week rank
0
IOCs

DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.

Loader
Type
Unknown
Origin
1 July, 2019
First seen
27 August, 2026
Last seen

How to analyze DonutLoader with ANY.RUN

Type
Unknown
Origin
1 July, 2019
First seen
27 August, 2026
Last seen

IOCs

IP addresses
48.209.138.168
150.171.27.11
209.99.191.153
40.126.32.136
188.114.96.3
20.190.160.14
172.211.123.249
2.18.69.150
104.18.23.222
150.171.109.100
52.123.224.74
150.171.109.104
128.24.231.65
74.179.77.164
48.209.133.15
23.11.41.157
48.209.138.189
2.16.164.9
23.197.136.177
150.171.109.193
Hashes
6f4ece9eef5c4e518ad56a6f82d14e95f93e4e5d07b1cb8d22de8666d7ac3d7f
4256488766553496d02c7dc5868938e34f24028f9841a5021560781e6f5b8d6e
298999caaa697082b5fd80903b1966482f211c921ab1ff74bb239c0db3337022
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
a8d081072ddd97380e854b9b664eaddcfafe6c28ee51c435f6d6b99919f1a105
3a5078b626e41d20117d260d8b825b039884cfe062c6d462432216d9b07d82b5
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
3dbd2c90050b652d63656481c3e5871c52261575292db77d4ea63419f187a55b
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
Domains
slscr.update.microsoft.com
edge.microsoft.com
edge-cloud-resource-static.azureedge.net
ocsp.digicert.com
edge-consumer-static.azureedge.net
self.events.data.microsoft.com
nexusrules.officeapps.live.com
go.microsoft.com
www.bing.com
p13n.adobe.io
msedge.b.tlu.dl.delivery.mp.microsoft.com
www.microsoft.com
settings-win.data.microsoft.com
sellercentrale-walmart.com
google.com
activation-v2.sls.microsoft.com
clients2.googleusercontent.com
api.edgeoffer.microsoft.com
fe3cr.delivery.mp.microsoft.com
config.edge.skype.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/ppsecure/deviceaddcredential.srf
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:jpqi_huuxo1bcokca-ecowghtgbstkoez8jwdvbztao&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://sellercentrale-walmart.com/v/view/form
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d251%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://update.googleapis.com/service/update2/json?cup2key=14:0hgai1egni6lv47wgkhv9gm_s98brvtdv8f8as0kjzc&cup2hreq=96b73e545c204fdf68d2b98a3f1fba465126e305f7b051e6a2eaa12adf0aee8e
https://clients2.googleusercontent.com/crx/blobs/abe5cl6a_jaanxapcjclooga79zaaqm3tadaaxpzgbj_5tef2gcwgawlwvojctwjy-62xnz5nkplhywefhkfca7ve1mtom8zrfv598knndu2neqdltxpxs0ljjjkmozedq0axlka5z-i_mcpvgwijs_fx-_dkkqdwg3y/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_109_1_0.crx
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2191
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6596
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10054
comments 0

Inside DonutLoader: Position-Independent Malware That Leaves Almost No Trace

Key Takeaways

  1. DonutLoader enables true fileless execution by converting any payload into position-independent shellcode that runs entirely in memory.
  1. It routinely bypasses AMSI, WLDP, and static scanners through dynamic API resolution and process injection.
  1. Primary infection vectors are social-engineering tactics such as ClickFix, fake CAPTCHA pages, and obfuscated BAT/PowerShell droppers.
  1. Sectors with high-value data (defense, healthcare, logistics, finance) face elevated risk due to targeted and mass campaigns.
  1. Successful attacks often combine DonutLoader with popular RATs and stealers, leading to rapid credential theft and ransomware deployment.
  1. ANY.RUN's Threat Intelligence Lookup to instantly investigate suspicious IPs, domains, or mutexes associated with DonutLoader, see targeted sectors and gather more IOCs.

domainName:"importenptoc.com".

Domain linked to DonutLoader in TI Lookup Domain linked to DonutLoader in TI Lookup

  1. Security teams can safely detonate and fully unpack multi-stage DonutLoader chains in ANY.RUN’s Interactive Sandbox, revealing in-memory behaviors invisible to traditional tools.

View analysis

DonutLoader malware analysis in Interactive Sandbox DonutLoader fresh sample analysis in Interactive Sandbox

What is DonutLoader Malware?

DonutLoader (also tracked as Donut or donut_injector) is a powerful, open-source in-memory loader and shellcode generator that has been widely adopted by cybercriminals and advanced threat actors alike.

Originally created for legitimate red-team and penetration testing purposes, DonutLoader converts .NET assemblies, EXE files, DLL files, VBScript, and JScript payloads into position-independent shellcode that executes directly in a target system's memory, never touching the disk. This means the malicious payload lives only in memory — it never persists on the file system in an easily detectable form.

The framework supports multiple output formats, including raw shellcode binaries, as well as execution via PowerShell, Python, Ruby, JavaScript, JScript, and VBScript. This versatility makes DonutLoader highly adaptable across attack campaigns and target environments. Threat actors can generate shellcode that loads virtually any Windows payload — from commodity RATs purchased on cybercrime forums to custom espionage implants developed by state-sponsored groups.

DonutLoader also features an array of built-in anti-detection and evasion capabilities. It can patch the Windows Antimalware Scan Interface (AMSI) to prevent security tools from inspecting script content before execution. It can disable Windows Lockdown Policy (WLDP) to allow arbitrary code execution in environments that would otherwise block it. It erases in-memory references to payloads after loading to hinder forensic analysis. Furthermore, it supports encryption, compression, and obfuscation of generated code modules, making static analysis and signature-based detection extremely difficult.

Because DonutLoader is publicly available on GitHub, it has a low barrier to entry for threat actors who do not need to develop their own custom loaders. It has been integrated into the toolchains of ransomware groups, APT actors, and commodity malware operators, cementing its status as a multi-purpose weapon in the modern threat landscape. MITRE ATT&CK tracks it under the identifier S0695, and it has been associated with multiple high-profile intrusion sets.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How DonutLoader Threatens Businesses and Organizations

By operating filelessly and injecting into trusted processes, DonutLoader defeats signature-based detection and many static analysis tools, allowing initial access to go unnoticed for hours or days. Once inside, it deploys payloads that steal credentials, exfiltrate sensitive data via Discord/Telegram webhooks, establish persistence, and open the door to ransomware or espionage. The result: financial losses from data breaches, operational downtime, regulatory fines, and reputational damage. Its low footprint also complicates incident response, as traditional forensic artifacts are minimal.

Victimology: Vulnerable Industries and Sectors

DonutLoader is used globally across both mass-distribution MaaS campaigns and targeted operations, making virtually any Windows environment at risk. Sectors particularly vulnerable include:

  • Defense and government contractors — frequently targeted for espionage (e.g., Symantec and Unit42 reports).

  • Healthcare — hit by ransomware groups like CrazyHunter in Taiwan. The sector's combination of sensitive data, operational urgency, and historically limited security resources makes it extremely vulnerable to DonutLoader-enabled ransomware attacks.

  • Logistics and manufacturing — targeted in GrayBravo/CastleLoader clusters.

  • Financial Services. Evil Corp — one of the threat groups confirmed to have used DonutLoader — originally focused on banking trojans and has repeatedly targeted financial institutions. The financial sector overall experienced a 47% year-over-year increase in observed attacks in 2024, making it one of the highest-risk verticals.

  • Technology companies — particularly software vendors and managed service providers — are frequently targeted because compromising a single vendor can enable downstream attacks on hundreds of clients. DonutLoader's in-memory execution is particularly effective in environments with sophisticated endpoint monitoring, as it reduces the observable footprint of the initial infection.

How Can Businesses Proactively Protect Against DonutLoader

  • Integrate TI Feeds as the first line of proactive defense: DonutLoader campaigns constantly rotate infrastructure and update payloads. ANY.RUN’s Threat Intelligence Feeds deliver a continuous, automated stream of fresh, high-confidence DonutLoader indicators — IPs, malicious domains, URLs, — sourced directly from real-time sandbox analysis of millions of malware submissions. These feeds are provided in standard formats (STIX/TAXII, CSV, JSON) and integrate directly into SIEMs, SOAR platforms, firewalls, EDR solutions, and TIP platforms.

By automatically blocking known DonutLoader infrastructure before shellcode execution begins, and by keeping detection rules current with the latest variants, TI Feeds transform an organization’s defenses from reactive to genuinely proactive.

TI Feeds benefits and integration TI Feeds: benefits, data sources, integration options

  • Block C2 communications before payloads execute: DonutLoader often downloads staged shellcode payloads from remote C2 servers over HTTP. TI Feeds continuously surface confirmed C2 indicators associated with active DonutLoader campaigns, enabling network perimeter controls — firewalls, web proxies, DNS sinkholes — to block these connections before the payload ever reaches memory. This network-layer kill switch is particularly powerful because it operates independently of endpoint detection capabilities.

  • Deploy behavioral and memory-based endpoint detection: Traditional file-scanning tools cannot detect DonutLoader. EDR and XDR solutions that monitor process behavior, memory injection patterns, API call sequences, and anomalous process relationships are essential complements to intelligence-driven IOC blocking — catching activity that may use novel infrastructure not yet in any feed.

  • Monitor and protect AMSI: DonutLoader patches AMSI in memory to prevent script scanning. Security teams should monitor for AMSI bypass attempts and consider kernel-level protection of security interfaces as a defense-in-depth layer beyond IOC blocking.

  • Enforce network segmentation and least-privilege access: Once DonutLoader delivers a RAT or Cobalt Strike beacon, attackers rely on lateral movement to reach high-value systems. Network segmentation, micro-segmentation, and strict privileged access management limit the blast radius of any infection that TI Feed-based controls did not intercept at the perimeter.

How DonutLoader Gets in the System and Functions

Initial access is almost always via social engineering:

  • Phishing emails with malicious ZIP/LNK/BAT attachments or links to fake software updates/CAPTCHA pages.

  • Malvertising, compromised websites, or sideloaded DLLs in legitimate-looking installers.

Once executed, an obfuscated BAT or PowerShell script downloads or decrypts the Donut shellcode, which then injects the final payload. Lateral movement and further spread depend on the delivered malware (RATs often enable it via SMB, RDP, or messaging apps), but the loader itself focuses on stealthy foothold establishment rather than worm-like propagation.

Shellcode Generation

DonutLoader takes a target payload — which can be a .NET assembly, a PE executable, a DLL, a VBScript, JScript, or any of several other supported file types — and converts it into position-independent shellcode. Position-independent code (PIC) does not rely on absolute memory addresses and can execute from any location in memory, making it inherently more portable and harder to predict or block.

Encryption and Obfuscation

Generated shellcode modules are encrypted, compressed, and encoded by default. This means that even if a defender extracts the shellcode from memory, it is not immediately readable or analyzable. Each generated module can use different encryption keys and configurations, reducing the effectiveness of static signatures built on previous samples.

AMSI and WLDP Patching

Before executing its payload, DonutLoader patches the Windows Antimalware Scan Interface (AMSI) by overwriting key functions in memory to return benign results regardless of what code is executed. It similarly disables the Windows Lockdown Policy (WLDP), which is designed to restrict execution of arbitrary code. These patches occur in memory and leave no disk artifacts, making them invisible to file-based scanning tools.

Reflective Code Loading and Process Injection

DonutLoader's core mechanism is reflective code loading — the ability to load and execute a PE file or .NET assembly from memory without relying on the Windows loader or writing anything to disk. The DonutTest subproject further enables process injection, allowing the shellcode to be injected into a chosen target process rather than running in a new process that might appear suspicious.

Indicator Removal

After the payload has been reflectively loaded and started executing, DonutLoader erases its own references from memory. Post-incident memory analysis may find the payload executing but struggle to trace it back to the original loader, complicating incident response and attribution efforts.

Remote Payload Download

DonutLoader can also download previously staged shellcode payloads from remote servers over HTTP, enabling operators to host payloads externally and update them without needing to re-infect the target system. This makes DonutLoader suitable for long-term persistent access scenarios.

Sandbox Analysis of DonutLoader Sample

The processes, scripts, modules, and network connections of DonutLoader are visible in ANY.RUN’s Interactive Sandbox safe detonations:

View analysis

DonutLoader sandbox analysis DonutLoader sample in the Interactive Sandbox

The sample is an obfuscated BAT script. The first part is a script whose task is to copy the BAT file into the user’s folder.

BAT script delivering malicious file BAT script delivering malicious file in the system

The executable PowerShell command is encoded in Base64 with added garbage sequences “llifd”. This PowerShell reads the entire BAT file as raw text and searches for a predefined marker that precedes the embedded Base64 payload, decodes it, and executes it via IEX. If the file is missing or the appropriate string is not found, this block does nothing.

PowerShell command leading to payload delivery PowerShell command leading to payload delivery

Regardless of the file check, the script reads the .bat file again and searches for another marker, after which it splits the received text into 2 parts. For each of the two parts, the following operations are performed:

    1. Decodes Base64.
    1. Decrypts AES.
    1. Unpacks gzip.
    1. Compiles, loads, and executes the assemblies.

Additionally, after the PowerShell stage, the process of compiling .NET assemblies is visible.

DonutLoader processes in the Interactive Sandbox DonutLoader processes in the Interactive Sandbox

Gathering Threat Intelligence on DonutLoader Malware

ANY.RUN's Threat Intelligence Lookup provides critical capabilities for detecting, investigating, and responding to DonutLoader threats:

Rapid IOC Validation and Enrichment

SOC analysts can query TI Lookup to instantly determine if an indicator is associated with known DonutLoader campaigns. The service provides contextual information including malware family classification, campaign attribution, and related artifacts - turning isolated indicators into actionable intelligence within seconds.

Deep Behavioral Analysis Access

TI Lookup gathers direct links to interactive sandbox sessions where DonutLoader was analyzed. Analysts can observe the complete execution chain. Start exploring with the threat name lookup:

threatName:"donut".

DonutLoader sandbox analyses Fresh DonutLoader sandbox analyses found via TI Lookup

YARA Rule Development and Testing

TI Lookup's integrated YARA Search allows security teams to scan ANY.RUN's threat intelligence database with custom detection rules. Teams can develop YARA rules targeting DonutLoader unique characteristics like mutex names and immediately test them against millions of analyzed samples to validate effectiveness and minimize false positives.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

DonutLoader exemplifies the shift toward fileless, memory-resident attacks that challenge traditional defenses. Its accessibility via open-source tools and integration into MaaS ecosystems ensures it will remain a staple in the attacker toolkit. Organizations that combine strong preventive controls with behavioral detection, proactive threat intelligence, and interactive malware analysis will stay ahead of this stealthy threat.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
MicroStealer screenshot
MicroStealer
microstealer
MicroStealer is a rapidly emerging infostealer first prominently observed in late 2025. It specializes in stealing browser credentials, active session data, screenshots, cryptocurrency wallets, and system information. It spreads quickly with low detection rates thanks to a sophisticated multi-stage delivery chain and exfiltrates data via Discord webhooks and attacker-controlled servers.
Read More
DoubleTrouble screenshot
DoubleTrouble
doubletrouble
DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More