A new malware campaign has been identified in which threat actors are distributing the GachiLoader and CountLoader malware through YouTube video links and cracked software distribution sites. Users are lured into clicking on malicious links embedded in YouTube videos or downloading pirated software, which initiates a multi-stage infection process. The campaign leverages social engineering and popular platforms to maximize reach and evade traditional detection methods.
Technical analysis reveals that the attack chain often begins with a ZIP archive containing a renamed Python interpreter, which executes malicious commands to retrieve CountLoader 3.2 using mshta.exe. The malware establishes persistence by creating scheduled tasks that mimic legitimate Google processes and adapts its behavior if security tools like CrowdStrike Falcon are detected. CountLoader is capable of delivering additional payloads such as Cobalt Strike, PureHVNC RAT, and Amatera Stealer, and the latest variants include features for host profiling and propagation via removable media.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers discovered a separate malware campaign dubbed the 'YouTube Ghost Network' that uses compromised or abused YouTube video links to distribute the Node.js-based GachiLoader malware. The loader was reported to use anti-analysis and PE injection techniques and to deliver malware such as the Rhadamanthys stealer, with DDoS-related capabilities also noted.
Security researchers identified a malware distribution campaign using cracked software websites to deliver CountLoader, a modular loader. The campaign was found to deploy payloads including ACR Stealer and to use persistence, evasion, fileless execution, and USB propagation techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.