HomeSecurityCountLoader: Russian hackers use new malware loader

CountLoader: Russian hackers use new malware loader

Cybersecurity researchers have discovered a new malware loader codenamed CountLoader, which has been used by Russian ransomware groups to deliver post-exploitation tools (e.g. Cobalt Strike and AdaptixC2) and the PureHVNC RAT trojan.

CountLoader

“ CountLoader is being used by either an Initial Access Broker (IAB) or a ransomware group working with LockBit, Black Basta, and Qilin ,” Silent Push said in an analysis.

CountLoader appears in three different versions – .NET, PowerShell, and JavaScript – and has been observed in a campaign targeting individuals in Ukraine. PDF-based phishing baits are used that impersonate the National Police of Ukraine.

See also: RaaS platform 'shinysp1d3r' encrypts VMware ESXi environments

CountLoader: PowerShell version

Kaspersky previously said that the PowerShell version of the malware is also distributed with DeepSeek. The attacks led to the development of an implant called BrowserVenom, which can reconfigure all browsing instances to pass traffic through a proxy server controlled by the threat actors. This allows them to manipulate network traffic and collect data.

CountLoader: JavaScript

Silent Push's research found that the JavaScript version is the most advanced implementation of the loader, offering six different methods for downloading files, three methods for executing various malware binaries, and a predefined function for identifying the victim's device based on Windows domain information.

The malware can collect system information, set up persistence on the computer by creating a scheduled task that impersonates a Google update task for the Chrome web browser, and connect to a remote server to await further instructions. These instructions can include the ability to download and execute DLL and MSI installer payloads using rundll32.exe and msiexec.exe, transmit system metadata, and delete the created scheduled task. The six methods used to download files include curl, PowerShell, MSXML2.XMLHTTP, WinHTTP.WinHttpRequest.5.1, bitsadmin, and certutil.exe.

See also: Pixie Dust Wi-Fi Attack: Exploiting WPS Routers

CountLoader: Russian hackers use new malware loader

“By using LOLBins such as 'certutil' and 'bitsadmin', and implementing an 'on the fly' PowerShell encryption command generator, CountLoader developers demonstrate an advanced understanding of the Windows operating system and malware development,” Silent Push reported.

CountLoader: .NET

A notable feature of CountLoader is its use of the Music as a staging area for the malware. The .NET version has some similarities to the JavaScript version, but only supports two different types of commands (UpdateType.Zip or UpdateType.Exe).

CountLoader is supported by an infrastructure consisting of over 20 unique domains, acting as a conduit for Cobalt Strike, AdaptixC2, and the PureHVNC RAT.

Recent campaigns distributing the PureHVNC RAT have leveraged the ClickFix social engineering tactic, luring victims to a phishing page with fake job offers (according to Check Point). The trojan is deployed via a Rust-based loader.

"The attacker misled the victim through fake job ads, allowing them to execute malicious PowerShell code via the ClickFix phishing technique," the cybersecurity firm said.

See also: Everest ransomware: Hackers say they breached BMW

CountLoader: Russian hackers use new malware loader

Protection from ClickFix attacks and malware

  • Educating users about social engineering tactics and phishing attacks
  • Install (and update) antivirus and anti-malware software on all endpoints
  • Implement powerful email filters to block phishing emails and malicious attachments
  • Use of firewalls and intrusion detection/prevention systems (IDS/IPS)
  • Network segmentation to limit the spread of malware
  • Implementation of the principle of least privilege (PoLP), so that users only have access to necessary resources
  • Updating operating systems, software and applications
  • Encryption of sensitive data
  • Continuous monitoring and analysis of system and network logs
Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS