logo

CountLoader Malware Weaponizes EtherHiding to Deploy Stealth Crypto Clippers

ID: 47876399-6364-5740-ae65-45ceaab97f6a

STIX ID: report--47876399-6364-5740-ae65-45ceaab97f6a

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Ddos

...
...

McAfee Labs uncovered a large CountLoader campaign that uses obfuscated JavaScript and staged PowerShell loaders to execute payloads in memory, disable AMSI, inject shellcode into legitimate processes, and deploy a cryptocurrency clipboard-clipper that swaps victim wallet addresses; operators fetch C2 via an Ethereum-based technique and researchers sinkholed a backup domain after thousands of infected hosts phoned home.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.