Netskope Threat Labs

Donut

ATP Sandbox Adv. HeuristicsAV

Donut is a .NET shellcode loader and exploit tool that cyberattackers use to convert .NET assemblies into position independent shellcode for in memory execution. The tool supports both native and managed payloads, includes options for decryption and anti analysis checks, and helps post exploitation tooling run without touching disk. Because it is a legitimate dual use project published openly, defenders should expect to see it in both authorized testing and intrusions.

First seen
January 2022
Last seen
October 2026

16 techniques across 5 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

TA0011 Command and Control

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
ByteCode-MSIL.Trojan.Donut
DeepScan:Generic.Exploit.Donut.2.1C03B540
DeepScan:Generic.Exploit.Donut.2.77A4E749
DeepScan:Generic.Exploit.Donut.3.B34E0292
Generic.Exploit.Donut.1.74CBEF75
Generic.Exploit.Donut.1.EBD9F840
Generic.Exploit.Donut.2.50F4F7F0
Generic.Exploit.Donut.2.6A6E7759
Generic.Exploit.Donut.2.91CA7D23
Generic.Exploit.Donut.2.B1A66C35