216.73.217.22

CountLoader: New Malware Loader Being Served in 3 Different Versions

· Published 19/09/2025 08:57 · Modified 19/09/2025 11:13

Export JSON

Essential information

Published
19/09/2025 08:57
Modified
19/09/2025 11:13
Tags
.net 2025-09-19 adaptixc2 cobaltstrike countloader evasion techniques initial access broker jscript lumma stealer malware loader phishing powershell purehvnc ransomware ukraine
Related entities
27 observables, 7 techniques (mitre), 5 malware, 1 others

Description

A new named has been identified, strongly associated with Russian gangs. It comes in three versions: .NET, , and . The threat is believed to be part of an 's toolset or used by a affiliate linked to LockBit, BlackBasta, and Qilin groups. was recently employed in a campaign targeting Ukrainian citizens, impersonating the Ukrainian police. The loader attempts to connect to multiple C2 servers, downloads and executes various malware payloads, and uses advanced techniques to evade detection. It has been observed dropping and , among other malicious tools. The malware's functionality includes system information gathering, persistence mechanisms, and multiple download methods.

External references