Donut is a tool tracked across 13 threat clusters and 21 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity July 23, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
JetBrains has issued patches for critical vulnerabilities in JetBrains Hub that could lead to full authentication bypass, account takeover, and privilege escalation. The vulnerabilities, tracked as CVE-2026-56141,…
Since late March 2026, a large-scale phishing campaign has been observed utilizing disguised TrueType Font (.ttf) files to deliver Lua-based loaders and various malware, including Agent Tesla and Remcos. The attackers…
Rapid7 identified a sophisticated malware campaign attributed to the threat actor 'Dropping Elephant,' leveraging China-themed decoy documents to deliver a revamped in-memory remote access trojan (RAT). The attack…
A new malware loader named 'Kiss Loader' has been identified, utilizing advanced process injection techniques, specifically Early Bird APC injection, to infiltrate Windows systems. The malware was first spotted in early…
Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations in Kazakhstan, the UAE, Syria, and Egypt, moving beyond their previous focus on Russian and Belarusian…
Threat actors are exploiting the decades-old 'finger' command in new ClickFix malware attacks to execute remote commands on Windows devices. The command, which was historically used to retrieve user information on Unix…
Chinese authorities have arrested 67 suspects linked to the Silver Fox cybercrime group, which primarily targeted Chinese-speaking users. The arrests occurred across five provinces, including Zhejiang, Jilin, Shandong,…
Foxveil is a newly identified malware loader first detected in August 2025. It utilizes legitimate platforms such as Discord, Cloudflare, and Netlify to stage Donut-generated shellcode, employing techniques like…
A multi-stage Windows malware campaign involving the Pulsar RAT has been reported, utilizing a concealed batch script, PowerShell loader, and Donut-generated shellcode for stealthy operations. The malware targets…