Find notable cyber news and cases, enriched with sources, timelines, and signals.

CountLoader malware loader used by Russian ransomware gangs for payload delivery

Malware Activity
First reported
Last updated
Happening score
H score 64
3 unique sources, 6 articles

Summary

Hide ▲

CountLoader has been observed in campaigns tied to Russian ransomware affiliates and linked to LockBit, Black Basta, and Qilin, with .NET, PowerShell, and JavaScript variants used to stage payloads such as Cobalt Strike, AdaptixC2, and PureHVNC RAT. Researchers also saw PDF phishing against individuals in Ukraine impersonating the National Police of Ukraine, where the JavaScript build could download and execute payloads, persist via a fake Chrome update task, and proxy traffic through attacker infrastructure. Later reporting described a separate campaign abusing cracked software sites and MediaFire ZIP archives to deliver CountLoader 3.2 and install ACR Stealer on Windows hosts. That chain used Setup.exe, mshta.exe, scheduled tasks, removable USB spread, and in-memory execution, while Silent Push said CountLoader was being used in active ransomware operations to deliver AdaptixC2 and that a DFIR case involved an Akira affiliate.

Related Happenings

Silver Fox tax-themed phishing campaign delivering ABCDoor and ValleyRAT

Campaign
H score36 First: 04.05.2026 14:57 Last: 04.05.2026 14:57 Sources 1

About this happening: Silver Fox is running a tax-themed phishing campaign that now targets India with Income Tax Department lures and delivers ValleyRAT (aka Winos 4.0). The campai...

Vidar infostealer market rise and distribution expansion

Malware Activity
H score30 First: 28.04.2026 22:07 Last: 28.04.2026 22:07 Sources 1

About this happening: Vidar remains a long-running infostealer threat, and Aryaka reported a fresh campaign in recent weeks that adds new obfuscation techniques and stronger steal...

AgingFly malware attacks local governments and hospitals in Ukraine

Malware Activity
H score28 First: 16.04.2026 00:57 Last: 16.04.2026 00:57 Sources 1

About this happening: The AgingFly malware is now being deployed against local governments and hospitals in Ukraine, where it steals browser and WhatsApp authentication data and enables dee...

JanelaRAT malware activity targeting Latin American banks

Malware Activity
H score29 First: 13.04.2026 20:15 Last: 13.04.2026 20:15 Sources 1

About this happening: JanelaRAT continues targeting Latin American banks and financial institutions, with telemetry showing 14,739 attacks in Brazil in 2025 and 11,695 in Mexico, ra...

Akira group rapid double-extortion ransomware activity

Malware Activity
H score45 First: 02.04.2026 16:00 Last: 02.04.2026 16:00 Sources 1

How related: A DFIR investigation found an Akira affiliate using the tool.

About this happening: Akira ransomware activity now includes AdaptixC2 abuse in active intrusions, adding another tool to a campaign already known for rapid double-extortion. A Silent Pus...

Timeline

  1. 19.12.2025 17:34 2 articles · 6mo ago

    New CountLoader campaign delivers ACR Stealer

    Campaign Scope Update

    A new CountLoader campaign abuses cracked software distribution sites and MediaFire ZIP archives to deliver CountLoader 3.2, using Setup.exe, mshta.exe, scheduled-task persistence, removable USB spread, and in-memory execution to install ACR Stealer on infected Windows hosts.

    Show sources
  2. 18.09.2025 15:56 5 articles · 10mo ago

    CountLoader loader used by Russian ransomware affiliates

    Initial Disclosure

    CountLoader is a new malware loader used by Russian ransomware gangs and affiliates tied to LockBit, Black Basta, and Qilin to deliver Cobalt Strike, AdaptixC2, and PureHVNC RAT; it appears in .NET, PowerShell, and JavaScript variants, has been seen in PDF-based phishing against individuals in Ukraine impersonating the National Police of Ukraine, and includes file-download, execution, persistence, and staging features such as scheduled-task persistence, a Music folder staging location, and traffic redirection through BrowserVenom.

    Show sources