Description
Donut is a .NET shellcode loader and exploit tool that cyberattackers use to convert .NET assemblies into position independent shellcode for in memory execution. The tool supports both native and managed payloads, includes options for decryption and anti analysis checks, and helps post exploitation tooling run without touching disk. Because it is a legitimate dual use project published openly, defenders should expect to see it in both authorized testing and intrusions.
Stats
- First seen
- January 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
16 techniques across 5 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Donut |
| DeepScan:Generic.Exploit.Donut.2.1C03B540 |
| DeepScan:Generic.Exploit.Donut.2.77A4E749 |
| DeepScan:Generic.Exploit.Donut.3.B34E0292 |
| Generic.Exploit.Donut.1.74CBEF75 |
| Generic.Exploit.Donut.1.EBD9F840 |
| Generic.Exploit.Donut.2.50F4F7F0 |
| Generic.Exploit.Donut.2.6A6E7759 |
| Generic.Exploit.Donut.2.91CA7D23 |
| Generic.Exploit.Donut.2.B1A66C35 |