HOLODONUT is a .NET-based modular backdoor associated with PeckBirdy-enabled intrusion activity and observed in campaigns tracked as SHADOW-VOID-044. It is deployed through a custom downloader known as NEXLOAD and is used as a secondary payload after initial compromise, including fake browser update lures delivered through compromised websites. The malware is designed to extend attacker access after initial intrusion and supports modular operation through server-delivered components or plugins.
HOLODONUT employs multiple defense-evasion measures. Reported execution chains include payload decryption followed by in-memory execution, use of Donut to run .NET assemblies without writing conventional artifacts to disk, and disabling or bypassing AMSI and ETW-related telemetry to reduce visibility to security tooling. Its role in the intrusion lifecycle is consistent with post-compromise remote access and flexible tasking through additional modules.
The malware has been linked to China-aligned activity through its use in SHADOW-VOID-044, a campaign targeting the Chinese gambling sector via watering-hole compromises and fake update delivery. It has also been assessed as likely related to WizardNet, a backdoor associated with the threat cluster known as TheWizard, indicating possible tooling overlap or shared development lineage among Chinese intrusion ecosystems. HOLODONUT targets Windows environments and functions as a modular backdoor for persistence, in-memory execution, and follow-on post-exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Delivered scripts observed include CVE-2020-16040 exploitation for Chrome, social engineering pop-ups, Electron JS backdoor delivery, and TCP reverse shell establishment.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Based on the infrastructure owned by the threat actors, we identified two distinct modular backdoors, HOLODONUT and MKDOOR, linked to SHADOW-VOID-044. HOLODONUT is a .NET-based modular backdoor we found within the threat actor’s infrastructure.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Next, the retrieved payload is decrypted via the XOR algorithm and executed by using the callback function, ”EnumWindows()”.
To execute HOLODONUT, the threat actors deployed a customized simple downloader used to retrieve the payload from the remote server downloader that we tracked as NEXLOAD... During the first initiation, the downloader will connect to the C&C server and download the backdoor module.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET modular backdoor delivered by the NEXLOAD downloader. It is decrypted with XOR and executed via EnumWindows(), uses AMSI and ETW disabling plus Donut-based in-memory execution for evasion, and supports plugin loading, execution, and unloading as well as basic info collection, sleep, and exit commands.
Modular backdoor used alongside PeckBirdy to extend post-compromise capability beyond the core script-based C2 framework.
.NET modular backdoor delivered by the NEXLOAD downloader; uses defense evasion (AMSI and ETW disabling) and Donut for in-memory .NET assembly execution; supports plugin handlers to dynamically load/execute/unload .NET assemblies.
An advanced modular backdoor delivered via PeckBirdy in a fake Chrome update/watering-hole style infection chain, used for persistent access and follow-on activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.