A large-scale CountLoader campaign that uses layered obfuscation, multi-stage payload delivery, and covert command-and-control (C2) communication to deploy cryptocurrency clipper malware.
The campaign stands out for its complex infection chain, combining JavaScript, PowerShell, and in-memory shellcode execution to evade detection and maintain persistence across infected systems.
The attack begins with a malicious executable that launches a PowerShell one-liner. This script downloads and decodes an obfuscated JavaScript loader that is executed via the legitimate Windows utility mshta.exe a commonly abused technique to bypass security controls.
Once active, the loader establishes persistence by creating scheduled tasks and begins communicating with multiple C2 servers.
McAfee Labs said in a report shared with GBhackers, a large-scale CountLoader campaign using multi-stage payload delivery and heavy obfuscation techniques.
It attempts connections in reverse order until a working server is found, ensuring resilience.
The payload delivery chain unfolds in several stages:
This fileless execution approach significantly reduces detection by traditional antivirus tools.
Researchers identified a flaw in the malware’s C2 communication mechanism and exploited it by registering a backup domain (hell10-kitty[.]cc), effectively sinkholing the traffic.
Sinkholing is a defensive technique where malicious domains are redirected to researcher-controlled infrastructure, allowing visibility into infected systems without alerting attackers.
Using this method, McAfee observed:
The malware uses a custom encrypted protocol for communication. Each message is encoded using a randomly generated six-digit key combined with XOR operations and Base64 encoding, making network-level detection more difficult.
In addition to network-based spread, CountLoader propagates through removable media. It replaces legitimate files on USB drives with malicious LNK shortcuts that execute the malware while opening the original file to avoid suspicion.
The malware supports multiple command types from its C2 server, including:
Telemetry suggests roughly 9,000 infections were linked to USB-based propagation.The PowerShell script executed by the launcher acts as a simple packer.
The final payload in this campaign is a cryptocurrency clipper a type of malware designed to hijack financial transactions. It continuously monitors clipboard activity and replaces copied wallet addresses with attacker-controlled ones.
To remain stealthy, the malware retrieves its C2 address using EtherHiding, a technique that leverages blockchain platforms like Ethereum to store and fetch malicious infrastructure data.
It also profiles infected systems by collecting information on installed cryptocurrency wallets and browser extensions, allowing attackers to prioritize high-value targets.
CountLoader ensures long-term persistence through scheduled tasks that execute every 30 or 60 minutes. It also adapts its behavior if security tools like CrowdStrike or Reason AV are detected, modifying execution patterns to avoid detection.
The use of trusted Windows utilities, heavy obfuscation, in-memory execution, and encrypted communications makes this campaign particularly difficult to detect and analyze.
This campaign highlights the growing sophistication of malware loaders and the increasing use of multi-layered techniques to deliver financially motivated payloads at scale.
| IOC |
|---|
| 5f9ff671955a6d551595f9838aed063c496da5039be0d222fe84f96cb3e1d32a |
| https://memory-scanner[.]cc/Presentation[.]pdf |
| 3c278499c5e3ced3bf1a6a7287808c5267075f1dec0aa5c7be2c4c444f33f2bc |
| https://memory-scanner[.]cc/ |
| https://hell1-kitty[.]cc/update1_usb_usb_usb[.]VOcx4wEV8 |
| c68e436d4cb984db026210806f50d0c81eec5f6e4860197dab91fab6f31ef796 |
| e2faad8111e7d47349cbc549b85e62231b8678057906bc813aad7242fa95ae63 |
| e5e1d8ec4cd109df290752ee3d4b2cbc9de6df4360e9983548f1bc6b1d088540 |
| hell1-kitty[.]cc |
| alphazero1-endscape[.]cc |
| api-microservice-us1[.]com |
| bucket-aws-s1[.]com |
| bucket-aws-s2[.]com |
| fileless-storage-s3[.]cc |
| globalsnn1-new[.]cc |
| globalsnn2-new[.]cc |
| globalsnn3-new[.]cc |
| handle-me-sv1[.]com |
| hardware-office[.]cc |
| health-smooth-eu1[.]com |
| health-smooth-eu2[.]com |
| health-smooth-eu3[.]com |
| holiday-updateservice[.]com |
| memory-protection-layer1[.]cc |
| memory-protection-layer2[.]cc |
| microservice-update-s1-bucket[.]cc |
| microservice-update-s2-bucket[.]cc |
| my-smart-house1[.]com |
| polystore9-servicebucket[.]cc |
| s3-updatehub[.]cc |
| 10593dbe9edfde7943fdaadd7882f190216b2f6502667daf701088a6e810deaf |
| 0a69a9cc75d65774e5eb90a4a739bd4335d33b176dc4923acb691bd45af66bdf |
| 27c6a6bda2c0ef3ecb78dad9c6bb7c3abaf2e32b3ad96f372a0102c0c9c0f08d |
| 2cd449f1bb24f05d2e240812a74bd62f2583bbbe4d0ccc9ae5736240e29a0068 |
| 30dcd5c71beb76d2f8df768d5fd9e9145cb8fbbfc951a63b969d26d3b64002b9 |
| dd4c7f5aae404816cf447b8090b620c1a1971a35c6791116aa3f871f00ae011b |
| 42a1fc74334c9a3b8720c79df55f84c7398bd31609eb10581e8c7155835498e3 |
| 9c0d334aac5a6f66016dc5ce8df75c46d519a4e6d16c68cf2b1405c81189186d |
| 44f6313e9542c0d51937a70160fe4137012905d8c79ad27ccc0021788ecfaa4e |
| https://hell1-kitty[.]cc/gamecenter[.]fileManager |
| https://hardware-office[.]cc/foundation[.]halflife |
| cbdfb46b9265a3dfb3bc6b0aade472dde28b1660dbd3ded3b67b1530b4497cca |
| 4a5e1d6ee1217e1fbacf54fc6017fbf9d24a25078266b02358d56a9c7437ceb7 |
| 05becb67d8bf1e49fcfccb0d346b82368a2b1c2bf07316078c364c7b020154de |
| 44daa1b68737b55a711963eec211c7c018bcba4cb6d68c286a4b45ea781a7d73 |
| dc602cb53a9c24abfcdaadf0ca8256b5fb5cac6d91d20ed8431bdaaf51c0cafe |
| https://edr-security-bucket1[.]cc/ |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…