| By Aditya K Sood and Bikash Dash | Aug 11, 2026 Aryaka Threat Research Lab examined a highly obfuscated Windows batch script that delivers Donut shellcode and installs a memory-resident .NET implant inside a legitimate Windows process. Threat Campaign Overview The infection begins with a malicious batch script that uses variable substitution, randomized labels, control-flow… The post Beyond the Batch File: A Look at a Multi-Stage DonutLoader Infection Chain appeared first on Aryaka . |