Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CountLoader: A Multifaceted Malware Loader Used by Russian Ransomware Gangs



The latest cybersecurity threat on the scene is none other than a multifaceted malware loader known as CountLoader, which Russian ransomware gangs are utilizing for their nefarious purposes. This highly sophisticated threat boasts numerous features that make it an attractive tool for attackers seeking to breach high-security systems, and its adaptability and resilience pose a significant challenge for security professionals.

  • CountLoader is a highly sophisticated malware loader used by Russian ransomware gangs.
  • The malware loader has been deployed with other tools like Cobalt Strike and AdaptixC2 to gain access to high-profile systems.
  • CountLoader boasts multiple versions, including .NET, PowerShell, and JavaScript, each with unique features.
  • The malware can gather system information, set up persistence, and connect to a remote server for further instructions.
  • It features advanced file downloading mechanisms and can transmit system metadata, delete scheduled tasks, and manage persistence.
  • CountLoader uses various methods to evade detection, including LOLBins and command encryption PowerShell generators.
  • The attackers are reportedly Russian ransomware gangs connected to groups like LockBit and Black Basta.
  • The malware loader has a unique ability to utilize a victim's Music folder as a staging ground for malware.
  • CountLoader has a large network of over 20 unique domains providing support for its operations.
  • The threat highlights the need for continuous vigilance among security professionals and the adaptation of threat actors to changing market conditions.



  • The cybersecurity landscape has recently been shaken by the emergence of a new and highly sophisticated malware loader known as CountLoader. This cutting-edge threat, which is being used by various Russian ransomware gangs, has caught the attention of cyber researchers and security experts alike due to its impressive capabilities and subtle methods of operation.

    According to recent investigations, CountLoader has been deployed in conjunction with other malware tools such as Cobalt Strike and AdaptixC2, among others. These tools enable attackers to gain access to a wide range of systems, including those belonging to high-profile organizations.

    The malware loader is known for its versatility, boasting multiple versions including .NET, PowerShell, and JavaScript. Each version boasts unique features that set it apart from other similar threats.

    One notable feature of the CountLoader malware loader is its ability to gather system information, set up persistence on the host by creating a scheduled task, and connect to a remote server for further instructions. This makes it an ideal tool for attackers looking to gain long-term access into compromised systems.

    In addition to these capabilities, CountLoader also features advanced file downloading mechanisms, allowing attackers to download and run DLL and MSI installer payloads using rundll32.exe and msiexec.exe, respectively. It can also transmit system metadata, delete the created scheduled task, and even manage persistence on the host.

    Furthermore, researchers have noted that the malware loader makes use of various methods to evade detection, including those that rely on the use of LOLBins like 'certutil' and 'bitsadmin', as well as an "on-the-fly" command encryption PowerShell generator. This demonstrates a high level of sophistication in terms of malware development.

    The malicious actors who have been using CountLoader are reportedly Russian ransomware gangs that share a connection with groups such as LockBit, Black Basta, and Qilin. The attackers used PDF-based phishing lures and impersonated the National Police of Ukraine to lure victims into downloading the malware loader.

    Interestingly, researchers found that the PowerShell version of the malware loader was previously flagged by Kaspersky as being distributed using DeepSeek-related decoys in order to trick users into installing it. Despite this, CountLoader has still managed to evade detection and gain widespread use among the attackers mentioned above.

    CountLoader is also notable for its unique ability to utilize a victim's Music folder as a staging ground for malware. This feature provides a high degree of flexibility and adaptability, which is further enhanced by the malware loader's capacity to download and execute files in various formats using an array of methods including curl, PowerShell, MSXML2.XMLHTTP, WinHTTP.WinHttpRequest.5.1, bitsadmin, and certutil.exe.

    In addition to its various capabilities, CountLoader also boasts a large network of over 20 unique domains that provide support for the malware loader's operations. These domains are used as conduits for communication between attackers and their victims.

    Researchers have discovered a notable aspect of CountLoader that reveals the strategic partnership between attackers using this malware loader and other threat actors such as PureCoder, who are known to utilize PureHVNC RAT, a commercial offering from the PureCoder group. This collaboration highlights the adaptable nature of modern cyber threats and the ease with which different groups can work together in order to achieve their objectives.

    In terms of its impact on cybersecurity, CountLoader serves as a stark reminder of the evolving landscape of malware and the need for continuous vigilance among security professionals. Its sophisticated methods of operation make it an attractive tool for attackers seeking to breach high-security systems.

    Moreover, researchers have also found that recent campaigns using PureHVNC RAT have leveraged tried-and-tested social engineering tactics such as ClickFix phishing. The attackers lured victims into downloading malware by impersonating fake job advertisements on the popular ClickFix job board.

    The discovery of CountLoader has led researchers to observe a significant trend in Russian ransomware operations and an apparent adaptation of threat actors to changing market conditions. It is clear that human capital plays a key role in these threats, with operators adapting their strategies in response to takedowns and reorganizing themselves as needed.

    In conclusion, the emergence of CountLoader highlights the relentless pursuit of sophisticated cyber threats by attackers seeking to exploit vulnerabilities in systems around the world. As security professionals, it is crucial that we remain vigilant and proactive in our efforts to stay ahead of these emerging threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CountLoader-A-Multifaceted-Malware-Loader-Used-by-Russian-Ransomware-Gangs-ehn.shtml

  • https://thehackernews.com/2025/09/countloader-broadens-russian-ransomware.html

  • https://www.secnews.gr/en/662643/countloader-rosikes-epixeiriseis-ransomware/


  • Published: Thu Sep 18 09:39:40 2025 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us