CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader
Researchers studying cybersecurity have found a new malware loader dubbed CountLoader that Russian ransomware gangs have been using to distribute a remote access trojan called PureHVNC RAT and post-exploitation tools like Cobalt Strike and AdaptixC2.
According to a study by Silent Push, CountLoader is being used by a ransomware affiliate with connections to the LockBit, Black Basta, and Qilin ransomware gangs, or as a component of an Initial Access Broker's (IAB) toolkit.
The growing threat, which comes in three separate versions—.NET, PowerShell, and JavaScript—has been seen in a campaign that impersonated the National Police of Ukraine and used PDF-based phishing lures to target people in Ukraine.
It is important to remember that Kaspersky previously identified the PowerShell v...

