A new campaign has been seen that uses phishing attempts to pose as Ukrainian government entities in order to deploy CountLoader, which is subsequently used to dump PureMiner and Amatera Stealer.
According to Yurren Wan, a researcher at Fortinet FortiGuard Labs, the phishing emails contain malicious Scalable Vector Graphics (SVG) files that are intended to fool recipients into opening dangerous attachments, as reported by The Hacker News.
A Compiled HTML Help (CHM) file is contained in a password-protected ZIP archive that is downloaded using the SVG files in the attack chains that the cybersecurity firm has documented. When the CHM file is started, a series of actions are initiated that lead to the deployment of CountLoader. According to the emails, the National Police of Ukraine has sent out a notice.
CountLoader has been identified to dump a variety of payloads, including Cobalt Strike, AdaptixC2, and PureHVNC RAT, according to a recent investigation conducted by Silent Push. However, it acts as a distribution channel for PureMiner read more about Researchers Expose Phishing Threats Distributing CountLoader and PureRAT.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
