logo

Beyond the Batch File: A Look at a Multi-Stage DonutLoader Infection Chain

ID: f42875e1-a18d-5e85-be7a-c82efcbb3837

STIX ID: report--f42875e1-a18d-5e85-be7a-c82efcbb3837

Feed Name: Aryaka

Threat Score
78/100

Date Published: 2026-08-11

Date Updated: 2026-08-11

Author: Aditya K Sood

...
...

### Executive summary Aryaka Threat Research Lab analyzed a multi-stage Windows malware campaign (DonutLoader) that starts from an obfuscated batch script, reconstructs and executes encrypted PowerShell payloads via a renamed powershell.exe, injects Donut-generated shellcode (marked by the custom marker DE AD BE CA FE BA EF) into explorer.exe to run a memory-resident .NET implant, establishes persistence via a scheduled task and VBS launcher, tampers with AMSI/ETW, and notifies operators via the Telegram Bot API while attempting outbound C2 to 167.88.167.9:8356. The report includes technical breakdowns, IOCs, MITRE ATT&CK mapping, and defensive guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.