Last seven days
- First activity
- Sep 29, 2026
- Last activity
- Oct 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 5 IP / 973 hostnames
DoubleDonut is a two-stage Donut-based malware loader observed by Rapid7 in a large ClickFix campaign that used compromised legitimate WordPress websites to infect visitors, primarily on Windows systems.
Profile source: Mallory opens in a new tabDoubleDonut
DoubleDonut is a two-stage Donut-based malware loader observed by Rapid7 in a large ClickFix campaign that used compromised legitimate WordPress websites to infect visitors, primarily on Windows systems. In this activity, attackers injected malicious JavaScript into WordPress sites or served it through WordPress admin-ajax endpoints, presenting a fake Cloudflare verification/CAPTCHA page that instructed users to paste a command into the Windows Run dialog. The resulting infection chain used PowerShell stagers to download shellcode such as cptch.bin and cptchbuild.bin, execute it in memory, and inject later stages into processes including svchost.exe. Rapid7 assessed that the campaign used the open-source Donut loader twice in sequence, referring to this component as โDoubleDonutโ or the โDoubleDonut Loader.โ
The campaign was described as active in this form since December 2025, with some supporting infrastructure dating to July/August 2025, and Rapid7 identified more than 250 compromised websites across at least 12 countries. DoubleDonut was used to deliver infostealer payloads including Vidar, a previously unnamed .NET stealer Rapid7 called Impure Stealer, and a newer C++ stealer dubbed VodkaStealer. The delivered payloads were capable of harvesting browser credentials, authentication cookies, cryptocurrency wallet data, and other sensitive information from infected devices. High-confidence infrastructure and infection-chain indicators mentioned in the reporting include 91.92.240[.]219, 178.16.53[.]70, 94.154.35[.]115, and later 172.94.9[.]187, along with shellcode filenames cptch.bin and cptchbuild.bin. The initial WordPress compromise vector was not confirmed, though weak administrator credentials and unpatched themes or plugins were cited as likely possibilities.
C2 tracking
Derp observations, rolling seven-day window
Samples
2dd3cb0cd831f4967f58e4915959fe5fd248a2428fbf529d0b673b27ebcbd0bf 460e44159c2115d337344c915e399f23537d29197a7accad4242a107dfd9ca89 4953a9ec9e1ea343056e3848bed5277aca80994d5fa38231fc322814927d5d5a 81a3f9296c5e5871b6d487b5f5d197f0cd554189a88350c0885749d55bac2a85 177b5f38233d8c3d3e928c192e0028db00c2249b37241ef202184f7de29d53d4 4a9c8a08ed51a1154ea23e641367f5db1b7d84b9e6224e1e89df7a458a46a725 976895cce2575bf6412f3523aefd7cc21e01e580ec5b071075cceb9e29e04263 c8a8d7857d3edd39c21b4a068e2ade118eed119d7480ad5e15612db266141f09 f4ab1cc92c0ed3f4f110dde27124660ad56af2cf683f5ba4fd3b62c4bf63cb47 29a601424f5fbcd3d068faa84ce6a96e9744842616f34772e4bc6874335dd5d7 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.