Cyber Security News

JavaScript Malware Campaign Drops Crypto Clipper via PowerShell

A large-scale CountLoader campaign that uses layered obfuscation, multi-stage payload delivery, and covert command-and-control (C2) communication to deploy cryptocurrency clipper malware.

The campaign stands out for its complex infection chain, combining JavaScript, PowerShell, and in-memory shellcode execution to evade detection and maintain persistence across infected systems.

The attack begins with a malicious executable that launches a PowerShell one-liner. This script downloads and decodes an obfuscated JavaScript loader that is executed via the legitimate Windows utility mshta.exe a commonly abused technique to bypass security controls.

Once active, the loader establishes persistence by creating scheduled tasks and begins communicating with multiple C2 servers.

McAfee Labs said in a report shared with GBhackers, a large-scale CountLoader campaign using multi-stage payload delivery and heavy obfuscation techniques. 

It attempts connections in reverse order until a working server is found, ensuring resilience.

The payload delivery chain unfolds in several stages:

  • JavaScript Loader (CountLoader): Executes via mshta.exe and initiates C2 communication.
  • PowerShell Packer: Decrypts and launches additional payload stages.
  • Injector: Disables security mechanisms such as AMSI and injects shellcode into legitimate processes.
  • Shellcode Execution: Loads the final payload directly into memory.
  • Final Payload: Runs under systeminfo.exe and deploys cryptocurrency clipper malware.

This fileless execution approach significantly reduces detection by traditional antivirus tools.

Researchers identified a flaw in the malware’s C2 communication mechanism and exploited it by registering a backup domain (hell10-kitty[.]cc), effectively sinkholing the traffic.

Sinkholing malware communication (Source : McAfee Labs).

Sinkholing is a defensive technique where malicious domains are redirected to researcher-controlled infrastructure, allowing visibility into infected systems without alerting attackers.

Using this method, McAfee observed:

  • Around 5,000 infected systems connecting per minute.
  • Approximately 86,000 unique infected machines globally.
  • A widespread geographic footprint, with the highest infections in India, followed by Indonesia, the United States, and Southeast Asia.

The malware uses a custom encrypted protocol for communication. Each message is encoded using a randomly generated six-digit key combined with XOR operations and Base64 encoding, making network-level detection more difficult.

JavaScript Malware Campaign

In addition to network-based spread, CountLoader propagates through removable media. It replaces legitimate files on USB drives with malicious LNK shortcuts that execute the malware while opening the original file to avoid suspicion.

Infection Chain (Source : McAfee Labs).

The malware supports multiple command types from its C2 server, including:

  • Executing EXE, DLL, MSI, HTA, and PowerShell files.
  • Spreading via USB drives.
  • Sending system and domain information back to attackers.
  • Self-uninstallation to evade analysis.

Telemetry suggests roughly 9,000 infections were linked to USB-based propagation.The PowerShell script executed by the launcher acts as a simple packer. 

Powershell Packer (Source : McAfee Labs).

The final payload in this campaign is a cryptocurrency clipper a type of malware designed to hijack financial transactions. It continuously monitors clipboard activity and replaces copied wallet addresses with attacker-controlled ones.

To remain stealthy, the malware retrieves its C2 address using EtherHiding, a technique that leverages blockchain platforms like Ethereum to store and fetch malicious infrastructure data.

It also profiles infected systems by collecting information on installed cryptocurrency wallets and browser extensions, allowing attackers to prioritize high-value targets.

CountLoader ensures long-term persistence through scheduled tasks that execute every 30 or 60 minutes. It also adapts its behavior if security tools like CrowdStrike or Reason AV are detected, modifying execution patterns to avoid detection.

The use of trusted Windows utilities, heavy obfuscation, in-memory execution, and encrypted communications makes this campaign particularly difficult to detect and analyze.

This campaign highlights the growing sophistication of malware loaders and the increasing use of multi-layered techniques to deliver financially motivated payloads at scale.

Indicators Of Compromise

IOC
5f9ff671955a6d551595f9838aed063c496da5039be0d222fe84f96cb3e1d32a
https://memory-scanner[.]cc/Presentation[.]pdf
3c278499c5e3ced3bf1a6a7287808c5267075f1dec0aa5c7be2c4c444f33f2bc
https://memory-scanner[.]cc/
https://hell1-kitty[.]cc/update1_usb_usb_usb[.]VOcx4wEV8
c68e436d4cb984db026210806f50d0c81eec5f6e4860197dab91fab6f31ef796
e2faad8111e7d47349cbc549b85e62231b8678057906bc813aad7242fa95ae63
e5e1d8ec4cd109df290752ee3d4b2cbc9de6df4360e9983548f1bc6b1d088540
hell1-kitty[.]cc
alphazero1-endscape[.]cc
api-microservice-us1[.]com
bucket-aws-s1[.]com
bucket-aws-s2[.]com
fileless-storage-s3[.]cc
globalsnn1-new[.]cc
globalsnn2-new[.]cc
globalsnn3-new[.]cc
handle-me-sv1[.]com
hardware-office[.]cc
health-smooth-eu1[.]com
health-smooth-eu2[.]com
health-smooth-eu3[.]com
holiday-updateservice[.]com
memory-protection-layer1[.]cc
memory-protection-layer2[.]cc
microservice-update-s1-bucket[.]cc
microservice-update-s2-bucket[.]cc
my-smart-house1[.]com
polystore9-servicebucket[.]cc
s3-updatehub[.]cc
10593dbe9edfde7943fdaadd7882f190216b2f6502667daf701088a6e810deaf
0a69a9cc75d65774e5eb90a4a739bd4335d33b176dc4923acb691bd45af66bdf
27c6a6bda2c0ef3ecb78dad9c6bb7c3abaf2e32b3ad96f372a0102c0c9c0f08d
2cd449f1bb24f05d2e240812a74bd62f2583bbbe4d0ccc9ae5736240e29a0068
30dcd5c71beb76d2f8df768d5fd9e9145cb8fbbfc951a63b969d26d3b64002b9
dd4c7f5aae404816cf447b8090b620c1a1971a35c6791116aa3f871f00ae011b
42a1fc74334c9a3b8720c79df55f84c7398bd31609eb10581e8c7155835498e3
9c0d334aac5a6f66016dc5ce8df75c46d519a4e6d16c68cf2b1405c81189186d
44f6313e9542c0d51937a70160fe4137012905d8c79ad27ccc0021788ecfaa4e
https://hell1-kitty[.]cc/gamecenter[.]fileManager
https://hardware-office[.]cc/foundation[.]halflife
cbdfb46b9265a3dfb3bc6b0aade472dde28b1660dbd3ded3b67b1530b4497cca
4a5e1d6ee1217e1fbacf54fc6017fbf9d24a25078266b02358d56a9c7437ceb7
05becb67d8bf1e49fcfccb0d346b82368a2b1c2bf07316078c364c7b020154de
44daa1b68737b55a711963eec211c7c018bcba4cb6d68c286a4b45ea781a7d73
dc602cb53a9c24abfcdaadf0ca8256b5fb5cac6d91d20ed8431bdaaf51c0cafe
https://edr-security-bucket1[.]cc/

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago