None
EN
CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader
['The Hacker News', 'Sep', 'Ravie Lakshmanan']
The Hacker News
Cybersecurity researchers have discovered a new malware loader codenamed CountLoader that has been put to use by Russian ransomware gangs to deliver post-exploitation tools like Cobalt Strike and AdaptixC2, and a remote access trojan known as PureHVNC RAT.
Silent Push told The Hacker News that it does not have any insight into the nature of malware that was dropped using CountLoader.
It's worth noting that the PowerShell version of the malware was previously flagged by Kaspersky as being distributed using DeepSeek-related decoys to trick users into installing it.
A notable aspect of CountLoader is its use of the victim's Music folder as a staging ground for malware.
"Brand allegiance among these operators is weak, and human capital appears to be the primary asset, rather than specific malware strains," DomainTools said.
['multiversion'
'russian'
'broadens'
'operations'
'ransomware'
'countloader'
'threat'
'victims'
'loader'
'task'
'system'
'powershell'
'using'
'purehvnc'
'different'
'malware']