donut_injector

Aliases: Donut

First seen
2020-01-01 00:00:00
Malware type
loader
Last IoC activity
2026-07-21 00:55:06
Profile updated
2026-07-07 14:43:11

Targeted industries: defense-and-aerospace government-and-public-sector

Targeted regions: country_code:us

Context

Donut is an open-source in-memory injector/loader, designed for execution of VBScript, JScript, EXE, DLL files and dotNET assemblies. It was used during attacks against U.S. organisations according to Threat Hunter Team (Symantec) and U.S. Defence contractors (Unit42). Github: https://github.com/TheWover/donut

Detection coverage

  • 2 YARA rules

Detection rules

  • HARFANGLAB_Donut_Shellcode (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_Donut (yara-rule)

Reports & references

  • cocomelonc.github.io — Malware Av Evasion 8 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Donut Injector (report)
  • st.drweb.com — Study Of A Targeted Attack On A Russian Rail Freight Operator En (report)
  • harfanglab.io — Supposed Grasshopper Operators Impersonate Israeli Gov Private Companies Deploy Open Source Malware (report)
  • swisspost-cybersecurity.ch — The Clickfix Deception (report)
  • Broadcom/Symantec — Wastedlocker Ransomware Us (report)
  • thewover.github.io — Introducing Donut (report)

External references