CountLoader Malware Weaponizes EtherHiding to Deploy Stealth Crypto Clippers
ID: 47876399-6364-5740-ae65-45ceaab97f6a
STIX ID: report--47876399-6364-5740-ae65-45ceaab97f6a
Feed Name: securityonline.info
Threat Score
McAfee Labs uncovered a large CountLoader campaign that uses obfuscated JavaScript and staged PowerShell loaders to execute payloads in memory, disable AMSI, inject shellcode into legitimate processes, and deploy a cryptocurrency clipboard-clipper that swaps victim wallet addresses; operators fetch C2 via an Ethereum-based technique and researchers sinkholed a backup domain after thousands of infected hosts phoned home.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
