Cybersecurity researchers have identified a sophisticated new malware loader called CountLoader, actively used by Russian ransomware gangs to infiltrate systems and deploy dangerous post-exploitation tools.
## What is CountLoader?
CountLoader serves as a gateway for cybercriminals to install secondary malware, including Cobalt Strike, AdaptixC2, and the PureHVNC remote access trojan (RAT). Security firm Silent Push reports that the malware is being utilized by Initial Access Brokers (IABs) and ransomware affiliates connected to major groups like LockBit, Black Basta, and Qilin.
## Multiple Attack Variants
The malware comes in three distinct versions:
– **.NET version**: A streamlined variant with basic functionality
– **PowerShell version**: Previously detected using DeepSeek-related decoys
– **JavaScript version**: The most advanced implementation with comprehensive capabilities
## Current Attack Campaigns
Recent campaigns have targeted Ukrainian individuals using PDF-based phishing emails that impersonate the National Police of Ukraine. These attacks demonstrate the malware’s versatility in social engineering tactics.
## Advanced Technical Capabilities
The JavaScript variant showcases sophisticated features:
– **Six different file download methods** using tools like curl, PowerShell, and certutil.exe
– **Three execution methods** for running malicious binaries
– **System reconnaissance** capabilities to identify victim devices
– **Persistence mechanisms** that mimic legitimate Google Chrome update tasks
CountLoader cleverly uses the victim’s Music folder as a staging area for malware deployment and employs “Living off the Land” binaries (LOLBins) to avoid detection.
## Infrastructure and Distribution
The malware operates through a network of over 20 unique domains and connects victims to dangerous tools including PureHVNC RAT, a commercial offering from the threat actor “PureCoder.” Recent campaigns have employed the ClickFix social engineering technique, luring victims through fake job advertisements.
## The Broader Russian Ransomware Ecosystem
Research by DomainTools reveals the interconnected nature of Russian ransomware operations, where threat actors frequently move between different groups. The investigation found that “brand allegiance among these operators is weak,” with human relationships and expertise being more valuable than specific malware tools.
## Key Takeaways
CountLoader represents the evolving sophistication of ransomware operations, combining advanced technical capabilities with effective social engineering. Organizations should remain vigilant against phishing attempts and implement robust security measures to defend against these multi-stage attacks.
The discovery highlights how Russian cybercriminal groups continue to adapt their tactics, sharing resources and expertise across different ransomware families to maximize their impact on global targets.
