donut_injector
Aliases: Donut
- First seen
- 2020-01-01 00:00:00
- Malware type
- loader
- Last IoC activity
- 2026-07-21 00:55:06
- Profile updated
- 2026-07-07 14:43:11
Targeted industries: defense-and-aerospace government-and-public-sector
Targeted regions: country_code:us
Context
Donut is an open-source in-memory injector/loader, designed for execution of VBScript, JScript, EXE, DLL files and dotNET assemblies. It was used during attacks against U.S. organisations according to Threat Hunter Team (Symantec) and U.S. Defence contractors (Unit42). Github: https://github.com/TheWover/donut
Detection coverage
- 2 YARA rules
Detection rules
- HARFANGLAB_Donut_Shellcode (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_Donut (yara-rule)
Reports & references
- cocomelonc.github.io — Malware Av Evasion 8 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Donut Injector (report)
- st.drweb.com — Study Of A Targeted Attack On A Russian Rail Freight Operator En (report)
- harfanglab.io — Supposed Grasshopper Operators Impersonate Israeli Gov Private Companies Deploy Open Source Malware (report)
- swisspost-cybersecurity.ch — The Clickfix Deception (report)
- Broadcom/Symantec — Wastedlocker Ransomware Us (report)
- thewover.github.io — Introducing Donut (report)