Malware
CountLoader
According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript. They believe it is part of an IAB toolset or used by a affiliate with ties to LockBit, BlackBasta, and Qilin ransomware groups. CountLoader was also recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.
Indicators of Compromise 3
MITRE ATT&CK TTPs 9
T1027 T1059.001 T1071.001 T1105 T1132.001 T1202 T1218.001 T1566 T1610
Obfuscated Files or Information
Defense Evasion
PowerShell
Execution
Web Protocols
Command And Control
Ingress Tool Transfer
Command And Control
Standard Encoding
Command And Control
Indirect Command Execution
Defense Evasion
Compiled HTML File
Defense Evasion
Phishing
Initial Access
Deploy Container
Defense Evasion