Donut

S0695

Tool.View on attack.mitre.org

About this tool

Donut is an open source framework used to generate position-independent shellcode. Donut generated code has been used by multiple threat actors to inject and load malicious payloads into memory.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1027.002
Software Packing

Donut can generate packed code modules.

T1027.013
Encrypted/Encoded File

Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules.

T1027.015
Compression

Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules.

T1055
Process Injection

Donut includes a subproject DonutTest to inject shellcode into a target process.

T1057
Process Discovery

Donut includes subprojects that enumerate and identify information about Process Injection candidates.

T1059
Command and Scripting Interpreter

Donut can generate shellcode outputs that execute via Ruby.

T1059.001
PowerShell

Donut can generate shellcode outputs that execute via PowerShell.

T1059.005
Visual Basic

Donut can generate shellcode outputs that execute via VBScript.

T1059.006
Python

Donut can generate shellcode outputs that execute via Python.

T1059.007
JavaScript

Donut can generate shellcode outputs that execute via JavaScript or JScript.

T1070
Indicator Removal

Donut can erase file references to payloads in-memory after being reflectively loaded and executed.

T1071.001
Web Protocols

Donut can use HTTP to download previously staged shellcode payloads.

T1105
Ingress Tool Transfer

Donut can download and execute previously staged shellcode payloads.

T1106
Native API

Donut code modules use various API functions to load and inject code.

T1620
Reflective Code Loading

Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. Donut Github Open source
    TheWover. (2019, May 9). donut. Retrieved March 25, 2022.
  2. Introducing Donut Open source
    The Wover. (2019, May 9). Donut - Injecting .NET Assemblies as Shellcode. Retrieved October 4, 2021.
  3. NCC Group WastedLocker June 2020 Open source
    Antenucci, S., Pantazopoulos, N., Sandee, M. (2020, June 23). WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group. Retrieved September 14, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.