Donut_injector is an open-source shellcode generation and injection framework first publicly released in 2019 by researcher TheWover (also known as odzhan), designed to execute .NET assemblies, PE files, and other payloads entirely in memory by creating position-independent shellcode. It belongs to the category of loader/stager tools commonly used by red teams and malware operators to bypass application whitelisting and AMSI detection, and has been widely adopted by ransomware groups such as BlackCat, as well as in Carbanak and FIN7 operations per Mandiant reports.
Donut_injector converts .NET executables, VBScript, JScript, XSL, and raw PE files into self-contained shellcode that can be executed through process injection (e.g., into rundll32.exe or regsvr32.exe) using standard Windows API calls without touching disk. It supports multiple injection techniques including reflective DLL injection, process hollowing, and thread execution hijacking, and integrates with C2 frameworks like Cobalt Strike (via the donut Aggressor script) and Sliver. The tool evades detection via AMSI patching, ETW (Event Tracing for Windows) bypass, and sandbox evasion checks (e.g., checking system uptime or debugger presence), and can encrypt payloads with XOR or AES-128 before injection. Its loader code is typically executed as shellcode via CreateRemoteThread, NtQueueApcThread, or callback functions (e.g., EnumDesktopsA), and it supports both x86 and x64 architectures with optional hypervisor detection.
Donut_injector was first documented by TheWover in a GitHub repository (security-risk-advisors/donut) in August 2019, and its version 1.0 was released later that year. In 2021, the Cobalt Strike Malleable C2 profile "donut" became prevalent in attacks, and Unit 42 (Palo Alto Networks) reported its use by the FIN7 group to deploy Carbanak backdoors in 2022. No direct CVEs exist for the loader itself, but it has been observed delivering ransomware payloads like BlackCat (ALPHV) in attacks targeting healthcare and critical infrastructure sectors as of 2023 (per CISA advisories).
Common indicators include shellcode patterns with a specific entropy signature (high entropy in .text sections of injected processes), mutex names such as GlobalMSCTF.CtfMonitor (spoofed) or custom ones created by the loader, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. Network IOCs typically involve HTTPS POST requests to C2 domains with User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (impersonating browsers). Known file hashes for donut-generated payloads are not static due to dynamic compilation, but YARA rules targeting the shellcode’s RC4/XOR decryption stubs are available from research teams (e.g., Joe Security).
Donut_injector itself is not destructive, but its use as a loader enables devastating ransomware deployments, credential theft, and lateral movement—leading to multi-million-dollar ransom demands and large-scale data exfiltration in incidents involving BlackCat and REvil affiliates. Financial services, healthcare, and government agencies have been most affected, with FBI alerts noting it was used to deliver LockBit samples in 2023.
Mitigation includes enabling AMSI in Windows Defender, deploying application control policies (e.g., WDAC or AppLocker) to block injection into trusted system binaries, and using EDR solutions with behavioral detection rules (e.g., Sigma rule ID 8f0e1c5a) that alert on suspicious CreateRemoteThread calls from mshta.exe or wscript.exe. Periodic memory scanning with tools like Volatility can identify injected shellcode regions.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.