Skip to content
ThreatCluster

CountLoader Malware Campaign Delivers Crypto Clipper via JavaScript and PowerShell

First seen 19 May 2026, 17:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 20, 2026 at 17:33 UTC
  • CountLoader campaign employs multi-stage payload delivery to deploy crypto clipper malware.
  • Attackers use JavaScript, PowerShell, and shellcode to maintain persistence and evade detection.
  • The malware campaign is actively draining cryptocurrency from users worldwide.

A large-scale malware campaign utilizing CountLoader has been discovered, deploying cryptocurrency clipper malware through a sophisticated infection chain. The attackers employ layered obfuscation and multi-stage payload delivery, leveraging JavaScript, PowerShell, and in-memory shellcode execution to evade detection. This campaign targets users globally, siphoning off cryptocurrency without detection. The attack begins with a malicious executable that initiates the infection process. Researchers have noted the complexity of the infection chain, which allows for persistence on infected systems. The scope of the impact is significant, affecting numerous users and potentially leading to substantial financial losses. The campaign is ongoing, with no immediate mitigation strategies reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 113d ago How this analysis works

Timeline

2026-05-19
CountLoader campaign identified
Researchers uncovered a large-scale malware campaign using CountLoader to deliver cryptocurrency clipper malware.
Gbhackers
2026-05-19
Malware delivery method detailed
The campaign utilizes JavaScript, PowerShell, and in-memory shellcode for a complex infection chain.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track CountLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed