logo

Hackers Deploy Crypto Clipper Using JavaScript and PowerShell Payloads

ID: 75e15260-5d20-5da5-a76c-6983ad14b395

STIX ID: report--75e15260-5d20-5da5-a76c-6983ad14b395

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Varshini

...
...

CountLoader is a multi-stage malware campaign that uses an initial malicious EXE to run obfuscated JavaScript and PowerShell (via mshta.exe) to deploy a cryptocurrency clipper that hijacks clipboard wallet addresses; the chain includes AMSI bypass, in-memory injection, USB propagation, and dynamic C2 retrieval via the Ethereum blockchain, and McAfee sinkholing observed roughly 86,000 unique infected machines with numerous IoCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.