CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader

Researchers studying cybersecurity have found a new malware loader dubbed CountLoader that Russian ransomware gangs have been using to distribute a remote access trojan called PureHVNC RAT and post-exploitation tools like Cobalt Strike and AdaptixC2.

According to a study by Silent Push, CountLoader is being used by a ransomware affiliate with connections to the LockBit, Black Basta, and Qilin ransomware gangs, or as a component of an Initial Access Broker’s (IAB) toolkit.

The growing threat, which comes in three separate versions—.NET, PowerShell, and JavaScript—has been seen in a campaign that impersonated the National Police of Ukraine and used PDF-based phishing lures to target people in Ukraine.

It is important to remember that Kaspersky previously identified the PowerShell version of the malware as being propagated using decoys related to DeepSeek that tricked victims into installing it read more about CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *