logo

Sinkholing CountLoader: Insights into Its Recent Campaign

ID: 89c39142-efed-5170-9794-9010bbadeb7b

STIX ID: report--89c39142-efed-5170-9794-9010bbadeb7b

Feed Name: McAfee Labs Blog

Threat Score
78/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: McAfee Labs

...
...

McAfee Labs uncovered a large-scale CountLoader campaign that uses multi-stage obfuscation (EXE → PowerShell → obfuscated HTA/JavaScript via mshta → PowerShell packer → injector → in-memory shellcode) to establish persistence, bypass security (AMSI disable), and contact encrypted C2s; the campaign deployed a cryptocurrency clipper that hijacks clipboard wallet addresses, spread via USB shortcuts, and had broad global reach (≈86,000 unique infections, ~5,000 connections/min, ~9,000 via removable media), with extensive IOCs and a sinkholed backup domain used for telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.