Netskope Threat Labs

Donoff

ATP Sandbox Adv. HeuristicsAV

Donoff is a malicious downloader distributed through malicious Office documents that delivers additional malware onto infected systems. The documents rely on malicious macros, and users who enable them trigger a chain that downloads follow on payloads from remote servers. The family has circulated for years as a generic first stage in campaigns that deliver bankers, stealers, and ransomware.

First seen
January 2022
Last seen
October 2026
Alert Name
Archive-JAR.Dropper.Donoff
ByteCode-JAVA.Downloader.Donoff
ByteCode-SWF.Trojan.Donoff
Document-Excel.Downloader.Donoff
Document-Excel.Dropper.Donoff
Document-Excel.Trojan.Donoff
Document-HTML.Downloader.Donoff
Document-HTML.Trojan.Donoff
Document-Office.Downloader.Donoff
Document-Office.Dropper.Donoff