Donut
MITRE ATT&CK: S0695 View on attack.mitre.org
Aliases: Donut
- Malware type
- loader
- Operating systems
- windows
- Related IoCs
- 2 (1 malicious)
- Last IoC activity
- 2026-01-11 09:45:08
- Profile updated
- 2026-07-07 13:42:27
Context
Donut is an open source framework used to generate position-independent shellcode. Donut generated code has been used by multiple threat actors to inject and load malicious payloads into memory.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Donut (S0695). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | http://88.99.48.80/donut/login.php | 2025-09-30 | 1 |
Detection coverage
- 624 Sigma rules
Malware & tools used
- Indicator Removal (attack-pattern)
- Python (attack-pattern)
- Process Injection (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Visual Basic (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Process Discovery (attack-pattern)
- Software Packing (attack-pattern)
- Web Protocols (attack-pattern)
- JavaScript (attack-pattern)
- Native API (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Compression (attack-pattern)
- PowerShell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Used by threat actors
- Indrik Spider (threat-actor)
Reports & references
- twitter.com — 1005438610806583296 (report)
- bleepingcomputer.com — The Week In Ransomware June 15Th 2018 Dbger Scarab And More (report)
- id-ransomware.blogspot.com — Donut Ransomware (report)
- research.nccgroup.com — Wastedlocker A New Ransomware Variant Developed By The Evil Corp Group (report)
- thewover.github.io — Introducing Donut (report)
- MITRE ATT&CK — S0695 (report)
- github.com — Donut (report)