Threats Tagged 'donut loader'
View all threats tagged with 'donut loader'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'donut loader'
Click on any threat for detailed analysis and mitigation recommendations
Between July and August 2026, a sophisticated campaign targeted organizations across East and Southeast Asia using Japanese and Korean-language phishing emails disguised as product damage complaints. Recipients were directed to fake document-sharing websites that delivered ZIP files containing malware. The archives contained executables with double extensions and DLLs implementing various loader techniques including customized Donut loaders, Python interpreters, AMSI/ETW bypasses, process hollowing, and BYOVD attacks using vulnerable Lenovo drivers. Despite varying loader implementations, the final payloads consistently delivered PureRAT or PureLogs malware families. The campaign demonstrated advanced evasion techniques by frequently changing loader structures while maintaining the same core payloads, effectively bypassing hash-based detection methods. Infrastructure analysis revealed common sending patterns through PHP Swift Mailer and shared Feedback-ID values across campaigns. Join the discussion | AlienVault OTX General | 09/25/2026, 15:41:27 UTC Added: 09/28/2026, 14:03:04 UTC |
Showing 1 to 1 of 1 result