Beyond the Batch File: A Look at a Multi-Stage DonutLoader Infection Chain
ID: f42875e1-a18d-5e85-be7a-c82efcbb3837
STIX ID: report--f42875e1-a18d-5e85-be7a-c82efcbb3837
Feed Name: Aryaka
### Executive summary Aryaka Threat Research Lab analyzed a multi-stage Windows malware campaign (DonutLoader) that starts from an obfuscated batch script, reconstructs and executes encrypted PowerShell payloads via a renamed powershell.exe, injects Donut-generated shellcode (marked by the custom marker DE AD BE CA FE BA EF) into explorer.exe to run a memory-resident .NET implant, establishes persistence via a scheduled task and VBS launcher, tampers with AMSI/ETW, and notifies operators via the Telegram Bot API while attempting outbound C2 to 167.88.167.9:8356. The report includes technical breakdowns, IOCs, MITRE ATT&CK mapping, and defensive guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
