Malware Campaign Uses JavaScript, PowerShell, and Shellcode to Deliver Crypto Clipper
ID: 96207c9e-cf49-5fe0-b7f2-98476ead5c09
STIX ID: report--96207c9e-cf49-5fe0-b7f2-98476ead5c09
Feed Name: cybersecurityNews.com
Researchers uncovered a large-scale CountLoader campaign that uses a multi-stage EXE → PowerShell → mshta/HTA → shellcode chain to deploy an in-memory cryptocurrency clipper which monitors and silently replaces wallet addresses; infections (≈86,000 unique machines, heavy activity in India, Indonesia, US) spread via internet and USB, use scheduled tasks and AMSI bypasses for persistence/stealth, and retrieve C2 addresses via the Ethereum blockchain (EtherHiding). The report includes detailed IoCs (hashes, domains, URLs) and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
