Listen to this Post

Introduction
A new cyber threat is rapidly gaining traction among Russian ransomware gangs, and its name is CountLoader. This malicious loader is being deployed to deliver powerful tools like Cobalt Strike, AdaptixC2, and PureHVNC RAT, which enable hackers to maintain persistence, steal data, and carry out large-scale ransomware operations. With different versions crafted in .NET, PowerShell, and JavaScript, CountLoader is proving to be a versatile and dangerous addition to the cybercriminal arsenal.
This article explores how CountLoader works, the ransomware groups leveraging it, and why cybersecurity experts consider it one of the most advanced emerging threats in 2025.
The Rise of CountLoader
Cybersecurity researchers have uncovered CountLoader, a malware loader currently being used by Russian ransomware affiliates. It primarily delivers post-exploitation tools like Cobalt Strike and AdaptixC2, along with the remote access trojan PureHVNC RAT.
Silent Push, a threat intelligence company, revealed that CountLoader is tied to LockBit, Black Basta, and Qilin ransomware groups, suggesting it could either belong to Initial Access Brokers (IABs) or be directly used by affiliates.
Multiple Versions of CountLoader
CountLoader appears in three forms:
.NET variant: A simplified version with limited command execution.
PowerShell variant: Distributed through DeepSeek-related decoys, previously flagged by Kaspersky.
JavaScript variant: The most advanced, featuring six file download methods, three execution strategies, and advanced victim identification.
Phishing Campaigns in Ukraine
Researchers observed CountLoader in phishing campaigns impersonating the National Police of Ukraine. Victims received malicious PDFs designed to trick them into installing the malware. Once inside the system, the loader could gather system details, maintain persistence via fake Google Chrome update tasks, and connect to attacker-controlled servers.
Advanced Capabilities
The malware demonstrates deep knowledge of Windows internals by abusing Living-off-the-Land Binaries (LOLBins) such as:
certutil.exe
bitsadmin
curl
MSXML2.XMLHTTP
WinHTTP.WinHttpRequest.5.1
It even uses the victim’s Music folder as a staging ground for additional payloads, making it less suspicious during scans.
PureHVNC RAT Connection
CountLoader is closely linked to PureHVNC RAT, a tool sold by a threat actor known as PureCoder. PureHVNC allows full remote control of infected systems and is considered a precursor to PureRAT (ResolverRAT). Recent campaigns used ClickFix phishing tactics with fake job offers, luring victims into running malicious PowerShell scripts.
Check Point researchers found that PureCoder relies on rotating GitHub accounts to host malware files, with timestamps pointing to the UTC+03:00 timezone — aligning with regions such as Russia.
Ransomware Ecosystem and Overlaps
DomainTools uncovered how different ransomware groups are interconnected, often sharing tools and human resources. Operators frequently switch allegiances, valuing trust and collaboration over brand loyalty. Tools like AnyDesk and Quick Assist were also spotted, suggesting that remote administration software is a common entry point for cybercriminals.
What Undercode Say:
Deep Integration of Malware Loaders
CountLoader represents a new era of modular malware loaders. Unlike older loaders, it does not just drop malware — it actively configures environments, persists stealthily, and dynamically executes different payloads depending on the victim profile.
LockBit and Black Basta Dependency
The fact that elite ransomware groups like LockBit and Black Basta are adopting CountLoader reveals its effectiveness in bypassing defenses. These groups only integrate tools that maximize success, showing that CountLoader is now a core part of the ransomware economy.
Phishing as the Primary Weapon
The reliance on social engineering tactics such as fake police notices and job offers highlights a simple truth: humans remain the weakest link in cybersecurity. CountLoader thrives not just on advanced coding but also on psychological manipulation of its targets.
Strategic Malware Development
The use of PowerShell generators with on-the-fly encryption demonstrates highly skilled malware authors. These features are not experimental — they are carefully engineered for real-world cybercrime efficiency.
Infrastructure and Resilience
With over 20 unique domains supporting its operations, CountLoader shows a resilient infrastructure. This decentralized model makes it harder for law enforcement to dismantle.
Human Capital Over Tools
The statement by DomainTools is telling — hackers are loyal to relationships, not brands. This fluidity explains why tools like CountLoader spread so fast across groups. If a skilled developer introduces a powerful loader, it quickly becomes the standard weapon across multiple ransomware organizations.
✅ Fact Checker Results
CountLoader has been confirmed by Silent Push, Kaspersky, and Check Point as a real and ongoing threat.
Its ties to LockBit, Black Basta, and Qilin are supported by intelligence findings.
The PureHVNC RAT connection is factually accurate and documented in multiple cybersecurity reports.
🔮 Prediction
CountLoader is likely to expand beyond Ukraine, evolving into a global threat. As ransomware operators refine their techniques, CountLoader will probably integrate with AI-driven phishing campaigns, making attacks even harder to detect. In the coming months, security experts may witness a spike in PureHVNC and PureRAT infections as CountLoader spreads further into Western targets.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: thehackernews.com
Extra Source Hub:
https://www.discord.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




