Donut

MITRE ATT&CK: S0695 View on attack.mitre.org

Aliases: Donut

Malware type
loader
Operating systems
windows
Related IoCs
2 (1 malicious)
Last IoC activity
2026-01-11 09:45:08
Profile updated
2026-07-07 13:42:27

Context

Donut is an open source framework used to generate position-independent shellcode. Donut generated code has been used by multiple threat actors to inject and load malicious payloads into memory.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Donut (S0695). The 1 most recently updated:

TypeIndicatorUpdatedSources
URL http://88.99.48.80/donut/login.php 2025-09-30 1

Detection coverage

  • 624 Sigma rules

Malware & tools used

  • Indicator Removal (attack-pattern)
  • Python (attack-pattern)
  • Process Injection (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Visual Basic (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Process Discovery (attack-pattern)
  • Software Packing (attack-pattern)
  • Web Protocols (attack-pattern)
  • JavaScript (attack-pattern)
  • Native API (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Compression (attack-pattern)
  • PowerShell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Used by threat actors

Reports & references

  • twitter.com — 1005438610806583296 (report)
  • bleepingcomputer.com — The Week In Ransomware June 15Th 2018 Dbger Scarab And More (report)
  • id-ransomware.blogspot.com — Donut Ransomware (report)
  • research.nccgroup.com — Wastedlocker A New Ransomware Variant Developed By The Evil Corp Group (report)
  • thewover.github.io — Introducing Donut (report)
  • MITRE ATT&CK — S0695 (report)
  • github.com — Donut (report)

External references