CountLoader Malware Campaign Delivers Crypto Clipper via JavaScript and PowerShell
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A large-scale malware campaign utilizing CountLoader has been discovered, deploying cryptocurrency clipper malware through a sophisticated infection chain. The attackers employ layered obfuscation and multi-stage payload delivery, leveraging JavaScript, PowerShell, and in-memory shellcode execution to evade detection. This campaign targets users globally, siphoning off cryptocurrency without detection. The attack begins with a malicious executable that initiates the infection process. Researchers have noted the complexity of the infection chain, which allows for persistence on infected systems. The scope of the impact is significant, affecting numerous users and potentially leading to substantial financial losses. The campaign is ongoing, with no immediate mitigation strategies reported.
Key Points: • CountLoader campaign employs multi-stage payload delivery to deploy crypto clipper malware. • Attackers use JavaScript, PowerShell, and shellcode to maintain persistence and evade detection. • The malware campaign is actively draining cryptocurrency from users worldwide.