Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
17
Global rank
15 infographic chevron month
Month rank
19 infographic chevron week
Week rank
0
IOCs

DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.

Loader
Type
Unknown
Origin
1 July, 2019
First seen
15 September, 2026
Last seen

How to analyze DonutLoader with ANY.RUN

Type
Unknown
Origin
1 July, 2019
First seen
15 September, 2026
Last seen

IOCs

IP addresses
23.3.89.90
95.100.102.101
74.178.76.128
48.209.138.168
95.100.102.9
172.66.175.107
74.178.76.54
20.190.159.128
48.192.1.65
2.16.164.10
40.126.32.68
23.11.41.157
2.16.164.11
204.79.197.203
23.59.18.102
31.220.89.57
172.211.123.248
2.23.246.101
57.153.246.3
48.192.1.64
Hashes
33c582e0be7ee6c2a995a84314e0057b65511d46c8c301893771a95f73f43f26
2537acf85084e161ebd88300a10575ac61fd8e454c0fc07ad2c0647c70b8953d
49f9a14a638c432d6a6a9aba4e83bafcc9265a2f6532c5ac8b1d1c1896fb5030
9b835cdb40d5ad6b8c9c998c9f679a01afd87a3d74598042f3ea00b173722410
8f94e60d88918ccf352e9d66e518bc7d37392018f1e5a51ff8965e0a97919e36
d49e176093a279cdbd7d8829de65f83b7d667c867f7c88e3c23c1479c5d128eb
4ab3d8f92e128c179e41f40043703d142ead980f5665a4e8fd56127113cdcc9c
63db7c93a0738c5f9659ea81d1bf1c69b86e392a9d8f47d374246b9111f6986b
b3d956fd403c263b62b22f430125afa2840f83fe1034d23755560a62bd7aa04d
91fd00d6df9a0814f67268642d45779ec63cb16116ba649f10daeb4c555a2238
d28b0476ba25b76e6e2c023d654371aab003467b23dfba7187507c93de3ef045
8793353461826fbd48f25ea8b835be204b758ce7510db2af631b28850355bd18
975b5678560775735da4a9e8b805dce370329179b8e17ebc1c289aaeb293f7ff
4bfa4c00414660ba44bddde5216a7f28aeccaa9e2d42df4bbff66db57c60522b
3c072532bf7674d0c5154d4d22a9d9c0173530c0d00f69911cdbc2552175d899
2b92ea2a7d2be8d64c84ea71614d0007c12d6075756313d61ddc40e4c4dd910e
8232c450f967d7f2f22c54582f0667f4c033ae62e6d450ff8a35c47486249443
f51a7acfffec56d6751561966d947d3fd199b74528c07dabdcf5fcb33d5b2e85
7852fce59c67ddf1d6b8b997eaa1adfac004a9f3a91c37295de9223674011fba
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
Domains
self.events.data.microsoft.com
ocsp.digicert.com
settings-win.data.microsoft.com
oneocsp.microsoft.com
www.microsoft.com
fe3cr.delivery.mp.microsoft.com
www.bing.com
slscr.update.microsoft.com
login.live.com
nexusrules.officeapps.live.com
google.com
activation-v2.sls.microsoft.com
client.wns.windows.com
ipwho.is
ecs.office.com
go.microsoft.com
crl.microsoft.com
cinaeddan03.com
edge-consumer-static.azureedge.net
shipnexa.info
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://ipwho.is/
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.2.crl
http://crl.microsoft.com/pki/crl/products/microoceraut_2010-06-23.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://www.bing.com/dsb/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=us&setlang=en-us&clientdatetime=9%2f15%2f2026%2c%205%3a40%3a47%20am
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/th?id=odswg.d36fb6d2-a1a9-40e9-b876-aabc05b76a5b&pid=dsb
Last Seen at

Recent blog posts

post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 438
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 5189
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 10301
comments 0

Inside DonutLoader: Position-Independent Malware That Leaves Almost No Trace

Key Takeaways

  1. DonutLoader enables true fileless execution by converting any payload into position-independent shellcode that runs entirely in memory.
  1. It routinely bypasses AMSI, WLDP, and static scanners through dynamic API resolution and process injection.
  1. Primary infection vectors are social-engineering tactics such as ClickFix, fake CAPTCHA pages, and obfuscated BAT/PowerShell droppers.
  1. Sectors with high-value data (defense, healthcare, logistics, finance) face elevated risk due to targeted and mass campaigns.
  1. Successful attacks often combine DonutLoader with popular RATs and stealers, leading to rapid credential theft and ransomware deployment.
  1. ANY.RUN's Threat Intelligence Lookup to instantly investigate suspicious IPs, domains, or mutexes associated with DonutLoader, see targeted sectors and gather more IOCs.

domainName:"importenptoc.com".

Domain linked to DonutLoader in TI Lookup Domain linked to DonutLoader in TI Lookup

  1. Security teams can safely detonate and fully unpack multi-stage DonutLoader chains in ANY.RUN’s Interactive Sandbox, revealing in-memory behaviors invisible to traditional tools.

View analysis

DonutLoader malware analysis in Interactive Sandbox DonutLoader fresh sample analysis in Interactive Sandbox

What is DonutLoader Malware?

DonutLoader (also tracked as Donut or donut_injector) is a powerful, open-source in-memory loader and shellcode generator that has been widely adopted by cybercriminals and advanced threat actors alike.

Originally created for legitimate red-team and penetration testing purposes, DonutLoader converts .NET assemblies, EXE files, DLL files, VBScript, and JScript payloads into position-independent shellcode that executes directly in a target system's memory, never touching the disk. This means the malicious payload lives only in memory — it never persists on the file system in an easily detectable form.

The framework supports multiple output formats, including raw shellcode binaries, as well as execution via PowerShell, Python, Ruby, JavaScript, JScript, and VBScript. This versatility makes DonutLoader highly adaptable across attack campaigns and target environments. Threat actors can generate shellcode that loads virtually any Windows payload — from commodity RATs purchased on cybercrime forums to custom espionage implants developed by state-sponsored groups.

DonutLoader also features an array of built-in anti-detection and evasion capabilities. It can patch the Windows Antimalware Scan Interface (AMSI) to prevent security tools from inspecting script content before execution. It can disable Windows Lockdown Policy (WLDP) to allow arbitrary code execution in environments that would otherwise block it. It erases in-memory references to payloads after loading to hinder forensic analysis. Furthermore, it supports encryption, compression, and obfuscation of generated code modules, making static analysis and signature-based detection extremely difficult.

Because DonutLoader is publicly available on GitHub, it has a low barrier to entry for threat actors who do not need to develop their own custom loaders. It has been integrated into the toolchains of ransomware groups, APT actors, and commodity malware operators, cementing its status as a multi-purpose weapon in the modern threat landscape. MITRE ATT&CK tracks it under the identifier S0695, and it has been associated with multiple high-profile intrusion sets.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

How DonutLoader Threatens Businesses and Organizations

By operating filelessly and injecting into trusted processes, DonutLoader defeats signature-based detection and many static analysis tools, allowing initial access to go unnoticed for hours or days. Once inside, it deploys payloads that steal credentials, exfiltrate sensitive data via Discord/Telegram webhooks, establish persistence, and open the door to ransomware or espionage. The result: financial losses from data breaches, operational downtime, regulatory fines, and reputational damage. Its low footprint also complicates incident response, as traditional forensic artifacts are minimal.

Victimology: Vulnerable Industries and Sectors

DonutLoader is used globally across both mass-distribution MaaS campaigns and targeted operations, making virtually any Windows environment at risk. Sectors particularly vulnerable include:

  • Defense and government contractors — frequently targeted for espionage (e.g., Symantec and Unit42 reports).

  • Healthcare — hit by ransomware groups like CrazyHunter in Taiwan. The sector's combination of sensitive data, operational urgency, and historically limited security resources makes it extremely vulnerable to DonutLoader-enabled ransomware attacks.

  • Logistics and manufacturing — targeted in GrayBravo/CastleLoader clusters.

  • Financial Services. Evil Corp — one of the threat groups confirmed to have used DonutLoader — originally focused on banking trojans and has repeatedly targeted financial institutions. The financial sector overall experienced a 47% year-over-year increase in observed attacks in 2024, making it one of the highest-risk verticals.

  • Technology companies — particularly software vendors and managed service providers — are frequently targeted because compromising a single vendor can enable downstream attacks on hundreds of clients. DonutLoader's in-memory execution is particularly effective in environments with sophisticated endpoint monitoring, as it reduces the observable footprint of the initial infection.

How Can Businesses Proactively Protect Against DonutLoader

  • Integrate TI Feeds as the first line of proactive defense: DonutLoader campaigns constantly rotate infrastructure and update payloads. ANY.RUN’s Threat Intelligence Feeds deliver a continuous, automated stream of fresh, high-confidence DonutLoader indicators — IPs, malicious domains, URLs, — sourced directly from real-time sandbox analysis of millions of malware submissions. These feeds are provided in standard formats (STIX/TAXII, CSV, JSON) and integrate directly into SIEMs, SOAR platforms, firewalls, EDR solutions, and TIP platforms.

By automatically blocking known DonutLoader infrastructure before shellcode execution begins, and by keeping detection rules current with the latest variants, TI Feeds transform an organization’s defenses from reactive to genuinely proactive.

TI Feeds benefits and integration TI Feeds: benefits, data sources, integration options

  • Block C2 communications before payloads execute: DonutLoader often downloads staged shellcode payloads from remote C2 servers over HTTP. TI Feeds continuously surface confirmed C2 indicators associated with active DonutLoader campaigns, enabling network perimeter controls — firewalls, web proxies, DNS sinkholes — to block these connections before the payload ever reaches memory. This network-layer kill switch is particularly powerful because it operates independently of endpoint detection capabilities.

  • Deploy behavioral and memory-based endpoint detection: Traditional file-scanning tools cannot detect DonutLoader. EDR and XDR solutions that monitor process behavior, memory injection patterns, API call sequences, and anomalous process relationships are essential complements to intelligence-driven IOC blocking — catching activity that may use novel infrastructure not yet in any feed.

  • Monitor and protect AMSI: DonutLoader patches AMSI in memory to prevent script scanning. Security teams should monitor for AMSI bypass attempts and consider kernel-level protection of security interfaces as a defense-in-depth layer beyond IOC blocking.

  • Enforce network segmentation and least-privilege access: Once DonutLoader delivers a RAT or Cobalt Strike beacon, attackers rely on lateral movement to reach high-value systems. Network segmentation, micro-segmentation, and strict privileged access management limit the blast radius of any infection that TI Feed-based controls did not intercept at the perimeter.

How DonutLoader Gets in the System and Functions

Initial access is almost always via social engineering:

  • Phishing emails with malicious ZIP/LNK/BAT attachments or links to fake software updates/CAPTCHA pages.

  • Malvertising, compromised websites, or sideloaded DLLs in legitimate-looking installers.

Once executed, an obfuscated BAT or PowerShell script downloads or decrypts the Donut shellcode, which then injects the final payload. Lateral movement and further spread depend on the delivered malware (RATs often enable it via SMB, RDP, or messaging apps), but the loader itself focuses on stealthy foothold establishment rather than worm-like propagation.

Shellcode Generation

DonutLoader takes a target payload — which can be a .NET assembly, a PE executable, a DLL, a VBScript, JScript, or any of several other supported file types — and converts it into position-independent shellcode. Position-independent code (PIC) does not rely on absolute memory addresses and can execute from any location in memory, making it inherently more portable and harder to predict or block.

Encryption and Obfuscation

Generated shellcode modules are encrypted, compressed, and encoded by default. This means that even if a defender extracts the shellcode from memory, it is not immediately readable or analyzable. Each generated module can use different encryption keys and configurations, reducing the effectiveness of static signatures built on previous samples.

AMSI and WLDP Patching

Before executing its payload, DonutLoader patches the Windows Antimalware Scan Interface (AMSI) by overwriting key functions in memory to return benign results regardless of what code is executed. It similarly disables the Windows Lockdown Policy (WLDP), which is designed to restrict execution of arbitrary code. These patches occur in memory and leave no disk artifacts, making them invisible to file-based scanning tools.

Reflective Code Loading and Process Injection

DonutLoader's core mechanism is reflective code loading — the ability to load and execute a PE file or .NET assembly from memory without relying on the Windows loader or writing anything to disk. The DonutTest subproject further enables process injection, allowing the shellcode to be injected into a chosen target process rather than running in a new process that might appear suspicious.

Indicator Removal

After the payload has been reflectively loaded and started executing, DonutLoader erases its own references from memory. Post-incident memory analysis may find the payload executing but struggle to trace it back to the original loader, complicating incident response and attribution efforts.

Remote Payload Download

DonutLoader can also download previously staged shellcode payloads from remote servers over HTTP, enabling operators to host payloads externally and update them without needing to re-infect the target system. This makes DonutLoader suitable for long-term persistent access scenarios.

Sandbox Analysis of DonutLoader Sample

The processes, scripts, modules, and network connections of DonutLoader are visible in ANY.RUN’s Interactive Sandbox safe detonations:

View analysis

DonutLoader sandbox analysis DonutLoader sample in the Interactive Sandbox

The sample is an obfuscated BAT script. The first part is a script whose task is to copy the BAT file into the user’s folder.

BAT script delivering malicious file BAT script delivering malicious file in the system

The executable PowerShell command is encoded in Base64 with added garbage sequences “llifd”. This PowerShell reads the entire BAT file as raw text and searches for a predefined marker that precedes the embedded Base64 payload, decodes it, and executes it via IEX. If the file is missing or the appropriate string is not found, this block does nothing.

PowerShell command leading to payload delivery PowerShell command leading to payload delivery

Regardless of the file check, the script reads the .bat file again and searches for another marker, after which it splits the received text into 2 parts. For each of the two parts, the following operations are performed:

    1. Decodes Base64.
    1. Decrypts AES.
    1. Unpacks gzip.
    1. Compiles, loads, and executes the assemblies.

Additionally, after the PowerShell stage, the process of compiling .NET assemblies is visible.

DonutLoader processes in the Interactive Sandbox DonutLoader processes in the Interactive Sandbox

Gathering Threat Intelligence on DonutLoader Malware

ANY.RUN's Threat Intelligence Lookup provides critical capabilities for detecting, investigating, and responding to DonutLoader threats:

Rapid IOC Validation and Enrichment

SOC analysts can query TI Lookup to instantly determine if an indicator is associated with known DonutLoader campaigns. The service provides contextual information including malware family classification, campaign attribution, and related artifacts - turning isolated indicators into actionable intelligence within seconds.

Deep Behavioral Analysis Access

TI Lookup gathers direct links to interactive sandbox sessions where DonutLoader was analyzed. Analysts can observe the complete execution chain. Start exploring with the threat name lookup:

threatName:"donut".

DonutLoader sandbox analyses Fresh DonutLoader sandbox analyses found via TI Lookup

YARA Rule Development and Testing

TI Lookup's integrated YARA Search allows security teams to scan ANY.RUN's threat intelligence database with custom detection rules. Teams can develop YARA rules targeting DonutLoader unique characteristics like mutex names and immediately test them against millions of analyzed samples to validate effectiveness and minimize false positives.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

DonutLoader exemplifies the shift toward fileless, memory-resident attacks that challenge traditional defenses. Its accessibility via open-source tools and integration into MaaS ecosystems ensures it will remain a staple in the attacker toolkit. Organizations that combine strong preventive controls with behavioral detection, proactive threat intelligence, and interactive malware analysis will stay ahead of this stealthy threat.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

UpCrypter screenshot
UpCrypter
upcrypter
UpCrypter is a sophisticated malware loader that functions as a delivery mechanism for remote access tools. Distributed through global phishing campaigns targeting Windows systems, this actively maintained tool serves as the central framework for deploying various RATs including PureHVNC, DCRat, and Babylon RAT, enabling attackers to establish persistent remote control over compromised systems.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
ClickFix screenshot
ClickFix is a sophisticated social engineering technique that tricks users into manually executing malicious commands on their devices. It masquerades as a "quick fix" for fake technical issues, CAPTCHA verifications, or error messages, often hijacking the clipboard to paste harmful PowerShell or terminal commands. This user-assisted approach helps it bypass traditional security controls, leading to infostealers like Lumma Stealer, RATs, and other malware.
Read More
CryptoWall screenshot
CryptoWall
cryptowall
CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More