Breakglass Intelligence reported that the CountLoader malware campaign used polyglot HTA files disguised as benign formats including .wav, .xml, .mp4, .ini, and .csv to trigger execution through mshta.exe on Windows. The loader combined layered obfuscation, sandbox and CrowdStrike Falcon-specific evasion, scheduled-task persistence, multiple payload download fallbacks, and a USB LNK worm capability. Its theft focus was unusually broad, targeting 76 cryptocurrency wallet browser extensions, 6 desktop wallet applications, and data from 66 Chromium-based browsers, while also retaining Active Directory reconnaissance modules that could support later enterprise compromise and ransomware activity.
Researchers said the operator rapidly evolved the campaign over several days, publishing 28 new samples to MalwareBazaar, rotating three of four known C2 IPs, adding new C2 domains and a tracking beacon, and simplifying the protocol in CountLoader v4.1.1 by removing a UTF-16LE layer while still exposing the XOR key in plaintext. Despite the churn, stable fingerprints such as a constant CLSID and unchanged wallet-stealing and reconnaissance modules persisted. The infrastructure used domains registered through NiceNIC, separate Cloudflare accounts and nameserver pairs for compartmentalization, and backend hosting across multiple providers, with earlier analysis tying five active C2 domains and one related domain to a single AlexHost IP in Moldova. Breakglass assessed the actor as a likely Russian-speaking cybercrime or MaaS operator with strong infrastructure management but only moderate payload-development sophistication.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
McAfee Labs registered the CountLoader backup domain hell10-kitty[.]cc and sinkholed malware traffic, observing about 5,000 connections per minute and roughly 86,000 unique infected machines. The analysis also found USB-spread via malicious LNK shortcuts affecting about 9,000 infections and documented the campaign deploying cryptocurrency clipper malware.
Analysis of the April 7 XWorm campaign found attribution signals pointing to a Brazilian operator, including Portuguese-language markers, a Brazilian DDNS domain, and a final C2 on a Telefonica Brasil residential IP. The staging infrastructure on magina.online was also found to expose MariaDB and FTP services, and notifications were sent to Hostinger, Telefonica Brasil, and BluePex/Winco.
A new XWorm campaign was first seen using a multi-stage chain with a 7z archive, obfuscated JavaScript, PowerShell hidden in an environment variable, steganographic JPEG payloads from magina.online, and a .NET loader named Fiber.Program. The final XWorm RAT was process-hollowed into Caspol.exe, with the loader reusing public HackForums process-hollowing code.
Between March 8 and March 12, the CountLoader operator rotated three of four known C2 IPs, added new C2 domains and a new tracking beacon, and published 28 additional samples to MalwareBazaar. Researchers also observed CountLoader v4.1.1 simplifying its protocol by removing a UTF-16LE layer while still exposing the XOR key in plaintext.
A coordinated CountLoader campaign was published to MalwareBazaar, using polyglot HTA files disguised as benign extensions to execute via mshta.exe on Windows. The malware targeted 76 cryptocurrency wallet browser extensions and 6 desktop wallet applications, while also stealing from 66 Chromium-based browsers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 133 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
mcafee.com
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.