Ethical Hacking News
A new phishing campaign has been uncovered that impersonates Ukrainian government agencies with malicious SVG files. The attack uses the CountLoader malware as a distribution vector for Amatera Stealer and PureMiner, which are both deployed as fileless threats. This phishing campaign serves as a reminder of the evolving nature of cyber threats, highlighting the importance of staying informed about emerging threats to protect against these attacks.
The Hacker News (THN) has exposed a new phishing campaign impersonating Ukrainian government agencies. The campaign distributes the CountLoader malware, which drops Amatera Stealer and PureMiner. The phishing emails contain malicious Scalable Vector Graphics (SVG) files designed to trick recipients into opening harmful attachments. CountLoader serves as a distribution vector for Amatera Stealer and PureMiner, which are part of a broader malware suite developed by PureCoder. Amatera Stealer and PureMiner are deployed as fileless threats using .NET Ahead-of-Time (AOT) compilation with process hollowing or loaded directly into memory using PythonMemoryModule. The phishing campaign demonstrates how a malicious SVG file can act as an HTML substitute to initiate an infection chain.
Cybersecurity news platform, The Hacker News (THN), has recently exposed a new phishing campaign that has been impersonating Ukrainian government agencies. This malicious campaign has been found to distribute the CountLoader malware, which then drops Amatera Stealer and PureMiner.
The phishing emails contain malicious Scalable Vector Graphics (SVG) files designed to trick recipients into opening harmful attachments. According to Fortinet FortiGuard Labs researcher Yurren Wan, "The phishing emails contain malicious SVG files designed to trick recipients into opening harmful attachments." The email messages claim to be a notice from the National Police of Ukraine.
Once the recipient opens the attachment, it initiates a chain of events that ultimately leads to the deployment of CountLoader. The email message contains a password-protected ZIP archive, which is launched by the CHM file inside. This activation process culminates in the deployment of CountLoader, which serves as a distribution vector for Amatera Stealer and PureMiner.
CountLoader has been found to drop various payloads like Cobalt Strike, AdaptixC2, and PureHVNC RAT. In this particular attack chain, it acts as a distribution vector for Amatera Stealer, a variant of ACRStealer, and PureMiner, a stealthy .NET cryptocurrency miner.
Interestingly, both PureHVNC RAT and PureMiner are part of a broader malware suite developed by a threat actor known as PureCoder. Some of the other products from this same author include PureCrypter, a crypter for Native and .NET; PureRAT (aka ResolverRAT), a successor to PureHVNC RAT; PureLogs, an information stealer and logger; BlueLoader, a malware that can act as a botnet by downloading and executing payloads remotely; and PureClipper, a clipper malware that substitutes cryptocurrency addresses copied into the clipboard with attacker-controlled wallet addresses to redirect transactions and steal funds.
According to Fortinet, Amatera Stealer and PureMiner are both deployed as fileless threats. These malicious payloads "executed via .NET Ahead-of-Time (AOT) compilation with process hollowing or loaded directly into memory using PythonMemoryModule."
Amatera Stealer, once launched, gathers system information, collects files matching a predefined list of extensions, and harvests data from Chromium- and Gecko-based browsers, as well as applications like Steam, Telegram, FileZilla, and various cryptocurrency wallets.
This phishing campaign demonstrates how a malicious SVG file can act as an HTML substitute to initiate an infection chain. In this case, attackers targeted Ukrainian government entities with emails containing SVG attachments. The SVG-embedded HTML code redirected victims to a download site.
The development comes as Huntress uncovered a likely Vietnamese-speaking threat group using phishing emails bearing copyright infringement notice themes to trick recipients into launching ZIP archives that lead to the deployment of PXA Stealer, which then evolves into a multi-layered infection sequence dropping PureRAT.
"This campaign demonstrates a clear and deliberate progression, starting with a simple phishing lure and escalating through layers of in-memory loaders, defense evasion, and credential theft," security researcher James Northey said. "The final payload, PureRAT, represents the culmination of this effort: a modular, professionally developed backdoor that gives the attacker complete control over a compromised host."
"Their progression from amateurish obfuscation of their Python payloads to abusing commodity malware like PureRAT shows not just persistence, but also hallmarks of a serious and maturing operator," Northey added.
The phishing campaign highlights the evolving nature of cyber threats. As attackers become more sophisticated in their tactics, cybersecurity measures must adapt to stay ahead of these new challenges.
In conclusion, this latest phishing campaign serves as a reminder of the ever-present threat of malware and phishing attacks. Cybersecurity experts must remain vigilant to stay informed about emerging threats like CountLoader, Amatera Stealer, and PureMiner.
Related Information:
https://www.ethicalhackingnews.com/articles/New-Phishing-Campaign-Exposed-Impersonation-of-Ukrainian-Government-Agencies-with-Malicious-SVG-Files-ehn.shtml
Published: Sat Sep 27 08:55:47 2025 by llama3.2 3B Q4_K_M