ThreatCluster

CountLoader Malware Campaign Delivers Crypto Clipper via JavaScript and PowerShell

First seen 19 May 2026, 17:57 UTC GbhackersCybersecuritynews 89% similarity 65

Article Content

Browse articles
ThreatCluster

A large-scale malware campaign utilizing CountLoader has been discovered, deploying cryptocurrency clipper malware through a sophisticated infection chain. The attackers employ layered obfuscation and multi-stage payload delivery, leveraging JavaScript, PowerShell, and in-memory shellcode execution to evade detection. This campaign targets users globally, siphoning off cryptocurrency without detection. The attack begins with a malicious executable that initiates the infection process. Researchers have noted the complexity of the infection chain, which allows for persistence on infected systems. The scope of the impact is significant, affecting numerous users and potentially leading to substantial financial losses. The campaign is ongoing, with no immediate mitigation strategies reported.

Key Points: • CountLoader campaign employs multi-stage payload delivery to deploy crypto clipper malware. • Attackers use JavaScript, PowerShell, and shellcode to maintain persistence and evade detection. • The malware campaign is actively draining cryptocurrency from users worldwide.

ThreatCluster AI

Timeline

2026-05-19
CountLoader campaign identified
Researchers uncovered a large-scale malware campaign using CountLoader to deliver cryptocurrency clipper malware.
Gbhackers
2026-05-19
Malware delivery method detailed
The campaign utilizes JavaScript, PowerShell, and in-memory shellcode for a complex infection chain.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story