#CountLoader
⚠️ ‘CountLoader’ is arming Russian ransomware (LockBit, Black Basta, Qilin)—dropping Cobalt Strike, AdaptixC2 & PureHVNC.

It spreads via fake Ukrainian police PDFs & DeepSeek lures, hijacks browsers, hides as “Google Update,” and abuses certutil/bitsadmin.
#CyberSecurity #InfoSec #Ransomware
CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader
CountLoader enables Russian ransomware gangs to deploy Cobalt Strike and PureHVNC RAT via Ukraine phishing campaigns.
thehackernews.com
September 18, 2025 at 1:01 PM
Silent Push has discovered a new malware loader named CountLoader that is currently being used by Russian-based initial access brokers in attacks that later deploy ransomware such as LockBit, BlackBasta, and Qilin

www.silentpush.com/blog/countlo...
CountLoader: Silent Push Discovers New Malware Loader Being Served in 3 Different Versions
Silent Push discovered a new malware loader, we're naming “CountLoader.” The threat is served in .NET, PowerShell, and JScript versions.
www.silentpush.com
September 18, 2025 at 11:02 AM
New Malware Loader ‘CountLoader’ Weaponized PDF File to Deliver Ransomware
New Malware Loader 'CountLoader' Weaponized PDF File to Deliver Ransomware
cybersecuritynews.com
September 19, 2025 at 9:53 AM
Hackers are using fake Ukrainian police emails to spread new #CountLoader malware, giving ransomware gangs like LockBit and Qilin initial access to victims.

Read: hackread.com/fake-ukraini...

#CyberSecurity #Russia #Ukraine #Ransomware
Fake Ukrainian Police Emails Spread New CountLoader Malware Loader
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
September 22, 2025 at 3:22 PM
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
New DOUBLECUP ClickFix service hides malware in browser cache images
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
www.bleepingcomputer.com
August 3, 2026 at 8:01 PM
-US seizes E-Note exchange
-India dismantles SMS factory
-17 malicious Firefox add-ons
-Google sues Darcula PhaaS
-Device-code phishing activity surges
-New Kimwolf botnet infets 1.83m deviecs
-RansomHouse uses double encryption
-Malware reports on Stealka, AuraStealer, CountLoader, GachiLoader
December 19, 2025 at 9:20 AM
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware thehackernews.com/2025/12/crac...
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware
Researchers uncover malware campaigns using cracked software and compromised YouTube videos to deliver CountLoader, GachiLoader, and info stealers.
thehackernews.com
December 24, 2025 at 9:12 PM
CountLoader: A New Malware Loader Linked to Russian Ransomware Groups
CountLoader: A New Malware Loader Linked to Russian Ransomware Groups
A new malware loader, CountLoader, is linked to Russian ransomware groups. The malware uses phishing lures impersonating the Ukrainian National Police to deliver payloads.
securityonline.info
September 22, 2025 at 3:24 AM
Your security tools might have missed this one. CountLoader is actively targeting networks right now — here's what you need to know before it hits yours.

Full analysis: threatchain.io/countloader-sample-detected-cx-programmer-9-1-free-download-full-exe-a3d56515

#cybersecurity #threatintelligenc...
April 29, 2026 at 7:18 PM
Weedhack malware targets Minecraft users via YouTube, SEO poisoning, and malicious JAR mods, using EtherHiding for multi-stage infection and data theft. Related campaigns include CountLoader and SilentCryptoMiner. #Weedhack #CountLoader #Minecraft
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
Researchers uncovered Weedhack, a Minecraft-themed malware-as-a-service campaign spread through YouTube and SEO poisoning that uses malicious JAR files, EtherHiding, and a multi-stage infection chain to steal data and enable remote control of victims’ systems. McAfee Labs also reported related campaigns including CountLoader infections and a pirated-content operation delivering SilentCryptoMiner, with #Weedhack...
www.hendryadrian.com
June 3, 2026 at 9:45 AM
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware

Cybersecurity researchers have disclosed details of a new campaign that has used cracked software distribution sites as a distribution vector for a new version of a modular and stealthy loader known as…
#hackernews #news
Cracked Software and YouTube Videos Spread CountLoader and GachiLoader Malware
Cybersecurity researchers have disclosed details of a new campaign that has used cracked software distribution sites as a distribution vector for a new version of a modular and stealthy loader known as CountLoader. The campaign "uses CountLoader as the initial tool in a multistage attack for access, evasion, and delivery of additional malware families," Cyderes Howler Cell Threat Intelligence
thehackernews.com
December 20, 2025 at 7:07 PM
Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper
cybersecuritynews.com/malware-camp...
Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper
CountLoader malware uses PowerShell and JavaScript to hijack crypto transactions on thousands of infected PCs.
cybersecuritynews.com
May 19, 2026 at 5:27 PM
Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam thehackernews.com/2025/09/rese...
Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam
SVG phishing emails drop CountLoader to deploy Amatera Stealer and PureMiner in Ukrainian government attack.
thehackernews.com
September 27, 2025 at 9:12 PM
Vírus invade sistemas via apps piratas e vídeos do YouTube | Seguranca www.tecmundo.com.br/seguranca/40...
Vírus invade sistemas via apps piratas e vídeos do YouTube
Campanhas CountLoader e GachiLoader exploram 39 contas comprometidas do YouTube e sites de pirataria, implementando técnicas de evasão que burlam todos os antivírus tradicionais
www.tecmundo.com.br
December 20, 2025 at 8:42 PM
JavaScriptマルウェアキャンペーン PowerShell経由で暗号資産クリッパーを配布

層状化された難読化、多段階ペイロード配信、隠蔽されたコマンド・アンド・コントロール(C2)通信を使用して暗号資産クリッパーマルウェアを配置する大規模なCountLoaderキャンペーン。 このキャンペーンは、JavaScript、PowerShell、メモリ内シェルコード実行を組み合わせて検出を回避し、感染したシス
JavaScriptマルウェアキャンペーン PowerShell経由で暗号資産クリッパーを配布
層状化された難読化、多段階ペイロード配信、隠蔽されたコマンド・アンド・コントロール(C2)通信を使用して暗号資産クリッパーマルウェアを配置する大規模なCountLoaderキャンペーン。 このキャンペーンは、JavaScript、PowerShell、メモリ内シェルコード実行を組み合わせて検出を回避し、感染したシス
blackhatnews.tokyo
May 19, 2026 at 7:38 AM
ハッカーがJavaScriptとPowerShellペイロードを使用して暗号資産クリッパーを展開

暗号資産盗難を目的とした大規模なCountLoaderマルウェアキャンペーン。脅威アクターは、難読化されたJavaScriptとPowerShellスクリプトを含む複雑なマルチステージ攻撃チェーンを使用して、セキュリティ防御を回避しています。 このキャンペーンの最終的な目的は、暗号資産クリッパーを展開することです。こ
ハッカーがJavaScriptとPowerShellペイロードを使用して暗号資産クリッパーを展開
暗号資産盗難を目的とした大規模なCountLoaderマルウェアキャンペーン。脅威アクターは、難読化されたJavaScriptとPowerShellスクリプトを含む複雑なマルチステージ攻撃チェーンを使用して、セキュリティ防御を回避しています。 このキャンペーンの最終的な目的は、暗号資産クリッパーを展開することです。こ
blackhatnews.tokyo
May 20, 2026 at 5:59 AM
New report details Russian Loader-as-a-Service designed to support ClickFix campaigns. The service enables operators to configure malicious lure pages that instruct victims to copy and execute commands from fake verification prompts.
rhisac.org/threat-intel...

#cybersecurity
#ClickFix
DOUBLECUP ClickFix Loader Delivers CountLoader and DeviceManager RATs - RH-ISAC
A SOCRadar Threat Research Unit report published on 3 August 2026 detailed DOUBLECUP, a Russian Loader-as-a-Service designed to support ClickFix campaigns.
rhisac.org
August 5, 2026 at 4:48 PM
Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper
Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper
A wave of well-crafted malware is quietly draining cryptocurrency from users across the globe, and the attackers behind it have gone to great lengths to stay hidden. Researchers have uncovered a large-scale campaign built around a multi-stage loader called CountLoader, which chains together JavaScript, PowerShell, and shellcode to deliver a payload that intercepts and redirects cryptocurrency transactions. The scope of this campaign is striking, with tens of thousands of machines now infected across multiple continents. The malware does not rely on a single trick. It starts with a malicious EXE file that runs a PowerShell command, pulling down an obfuscated JavaScript loader and executing it through mshta.exe, a legitimate Windows utility that attackers frequently abuse because the operating system trusts it by default. This lets the malware blend into normal activity, giving it time to settle in before any defenses can respond. Analysts at McAfee Labs, who authored the research and shared details in a report  with Cyber Security News (CSN), noted that the campaign reached roughly 86,000 unique infected machines. On average, around 5,000 infected systems were connecting to command-and-control infrastructure every single minute. Infections were highest in India, followed by Indonesia and the United States, with a strong presence across Southeast Asia. Beyond internet-based delivery, the malware also spreads through USB drives. When instructed by its command server, CountLoader replaces files on connected external drives with LNK shortcut files. Malware Campaign Deliver Crypto Clipper Opening one silently runs the malware while also opening the original file, so victims notice nothing unusual. About 9,000 infections were traced back to this USB-based method. The end goal is a cryptocurrency clipper. Once loaded into memory, it monitors the clipboard in the background. The moment a user copies a wallet address, the clipper replaces it with one controlled by the attacker, silently rerouting funds with no visible warning to the victim. The infection chain is designed to avoid detection at every stage. After the initial EXE runs, a scheduled task fires every 30 minutes to maintain persistence from the very first step. Infection Chain (Source – McAfee) The PowerShell script then decodes a Base64 payload and runs it using Invoke-Expression, a common technique for executing hidden code without writing anything to disk. CountLoader then takes control as an HTA file loaded through mshta.exe. It hides its window, attempts to erase its own file if run locally, and cycles through command servers until one responds. Once connected, it performs an encrypted handshake, grabs a JWT token, and sends back details about the infected host, including any installed cryptocurrency wallets or browser extensions. The next stages involve a PowerShell packer that decrypts and launches a shellcode injector. Before injecting, the script disables AMSI, a Windows feature designed to catch malicious scripts , using a known public bypass. The shellcode then loads the final payload directly into memory under systeminfo.exe, never touching the disk, making it significantly harder for security tools to detect. Cryptocurrency Clipper Delivered via EtherHiding What sets the final payload apart is how it locates its command server. Rather than hard-coding a domain that can be blocked or taken down, the clipper uses a technique called EtherHiding, fetching the server address straight from the Ethereum blockchain. Since the blockchain is decentralized, there is no single point defenders can shut down to cut the malware off. Global Distribution of CountLoader Infections (Source – McAfee) Once the server address is retrieved, the clipper silently monitors clipboard contents and supports multiple cryptocurrency formats, meaning it can swap Bitcoin, Ethereum, and other wallet addresses without the victim noticing. Researchers measured the true scale of this campaign by registering a backup C2 domain and sinkholing infected traffic to their own server, effectively turning the attackers’ infrastructure against them. To reduce risk, users should avoid running EXE files from untrusted sources, treat unknown USB drives with caution, and always verify wallet addresses before sending cryptocurrency . Watching for unfamiliar scheduled tasks on Windows and keeping security software updated can also help detect this threat before serious damage is done. Indicators of Compromise (IoCs):- Type Indicator Description File Hash (SHA256) 5f9ff671955a6d551595f9838aed063c496da5039be0d222fe84f96cb3e1d32a EXE Stage 1 URL https://memory-scanner[.]cc/Presentation[.]pdf PowerShell Stage 2 download URL File Hash (SHA256) 3c278499c5e3ced3bf1a6a7287808c5267075f1dec0aa5c7be2c4c444f33f2bc PowerShell Stage 2 script URL https://memory-scanner[.]cc/ CountLoader download URL URL https://hell1-kitty[.]cc/update1_usb_usb_usb[.]VOcx4wEV8 CountLoader download URL File Hash (SHA256) c68e436d4cb984db026210806f50d0c81eec5f6e4860197dab91fab6f31ef796 CountLoader v3.3 File Hash (SHA256) e2faad8111e7d47349cbc549b85e62231b8678057906bc813aad7242fa95ae63 CountLoader v4.1 File Hash (SHA256) e5e1d8ec4cd109df290752ee3d4b2cbc9de6df4360e9983548f1bc6b1d088540 CountLoader v4.1 Domain hell1-kitty[.]cc CountLoader C2 domain Domain alphazero1-endscape[.]cc CountLoader C2 domain Domain api-microservice-us1[.]com CountLoader C2 domain Domain bucket-aws-s1[.]com CountLoader C2 domain Domain bucket-aws-s2[.]com CountLoader C2 domain Domain fileless-storage-s3[.]cc CountLoader C2 domain Domain globalsnn1-new[.]cc CountLoader C2 domain Domain globalsnn2-new[.]cc CountLoader C2 domain Domain globalsnn3-new[.]cc CountLoader C2 domain Domain handle-me-sv1[.]com CountLoader C2 domain Domain hardware-office[.]cc CountLoader C2 domain Domain health-smooth-eu1[.]com CountLoader C2 domain Domain health-smooth-eu2[.]com CountLoader C2 domain Domain health-smooth-eu3[.]com CountLoader C2 domain Domain holiday-updateservice[.]com CountLoader C2 domain Domain memory-protection-layer1[.]cc CountLoader C2 domain Domain memory-protection-layer2[.]cc CountLoader C2 domain Domain microservice-update-s1-bucket[.]cc CountLoader C2 domain Domain microservice-update-s2-bucket[.]cc CountLoader C2 domain Domain my-smart-house1[.]com CountLoader C2 domain Domain polystore9-servicebucket[.]cc CountLoader C2 domain Domain s3-updatehub[.]cc CountLoader C2 domain File Hash (SHA256) 10593dbe9edfde7943fdaadd7882f190216b2f6502667daf701088a6e810deaf USB LNK file File Hash (SHA256) 0a69a9cc75d65774e5eb90a4a739bd4335d33b176dc4923acb691bd45af66bdf USB LNK file File Hash (SHA256) 27c6a6bda2c0ef3ecb78dad9c6bb7c3abaf2e32b3ad96f372a0102c0c9c0f08d USB LNK file File Hash (SHA256) 2cd449f1bb24f05d2e240812a74bd62f2583bbbe4d0ccc9ae5736240e29a0068 USB LNK file File Hash (SHA256) 30dcd5c71beb76d2f8df768d5fd9e9145cb8fbbfc951a63b969d26d3b64002b9 USB LNK file File Hash (SHA256) dd4c7f5aae404816cf447b8090b620c1a1971a35c6791116aa3f871f00ae011b USB LNK file File Hash (SHA256) 42a1fc74334c9a3b8720c79df55f84c7398bd31609eb10581e8c7155835498e3 USB LNK file File Hash (SHA256) 9c0d334aac5a6f66016dc5ce8df75c46d519a4e6d16c68cf2b1405c81189186d USB LNK file File Hash (SHA256) 44f6313e9542c0d51937a70160fe4137012905d8c79ad27ccc0021788ecfaa4e USB LNK file URL https://hell1-kitty[.]cc/gamecenter[.]fileManager Payload launcher URL URL https://hardware-office[.]cc/foundation[.]halflife Payload launcher URL File Hash (SHA256) cbdfb46b9265a3dfb3bc6b0aade472dde28b1660dbd3ded3b67b1530b4497cca Payload launcher File Hash (SHA256) 4a5e1d6ee1217e1fbacf54fc6017fbf9d24a25078266b02358d56a9c7437ceb7 PowerShell packer File Hash (SHA256) 05becb67d8bf1e49fcfccb0d346b82368a2b1c2bf07316078c364c7b020154de Shellcode injector File Hash (SHA256) 44daa1b68737b55a711963eec211c7c018bcba4cb6d68c286a4b45ea781a7d73 Shellcode File Hash (SHA256) dc602cb53a9c24abfcdaadf0ca8256b5fb5cac6d91d20ed8431bdaaf51c0cafe Final clipper payload URL https://edr-security-bucket1[.]cc/ Payload C2 server URL Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper appeared first on Cyber Security News .
cybersecuritynews.com
May 19, 2026 at 6:48 PM
Adaptix Ties to Russian Criminal Underworld, Threat Actors Harness Open-Source Tool for Malicious Payload

Silent Push has published new research in which its threat analysts uncover threat actors using Adaptix, a free and open source tool commonly used by penetration testers, to deliver malicious…
Adaptix Ties to Russian Criminal Underworld, Threat Actors Harness Open-Source Tool for Malicious Payload
Silent Push has published new research in which its threat analysts uncover threat actors using Adaptix, a free and open source tool commonly used by penetration testers, to deliver malicious payloads. Silent Push has observed heavy ties linking Adaptix to Russia and the Russian criminal underworld.  Abuse of Adaptix was first discovered during Silent Push's research on the new malware CountLoader, which they…
itnerd.blog
October 30, 2025 at 1:24 PM
DOUBLECUP is a new Russian ClickFix Loader-as-a-Service that drops CountLoader and the DeviceManager RAT using steganography and EtherHiding.

#DOUBLECUP #ClickFix #CountLoader #DeviceManager #EtherHiding #CyberSecurity
DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT
At a Glance
securityonline.info
August 11, 2026 at 6:43 AM
New Russian LaaS 'DOUBLECUP' uses steganography to hide malware (CountLoader, DeviceManager RAT) in PNG images. 'ClickFix' attacks trick users into pasting commands that extract the payload from browser cache. #Malware #LaaS #Steganography

🌐 cyber[.]netsecops[.]io
New
A new Loader-as-a-Service called DOUBLECUP uses steganography to hide malware like CountLoader and DeviceManager RAT inside PNG images stored in browser...
cyber.netsecops.io
August 6, 2026 at 11:23 PM