PULSE NAME
IOC - Sinkholing CountLoader: Insights into Its Recent Campaign
WHITE celestre 2026-05-20 Modified: 2026-05-20
51
IOCs
HIGH VOLUME
McAfee Labs has recently uncovered a large scale CountLoader campaign that uses multiple layers of obfuscation and staged payload delivery to evade detection and maintain persistence in infected systems. The infection process relies on several layers of loaders, including PowerShell scripts, obfuscated JavaScript executed through mshta.exe, and in memory shellcode injection, each stage decrypting and launching the next. The attackers employ a custom encrypted communication protocol to interact with their C2 servers.
Indicators of Compromise (1 / 51 total)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 078ec2c1e9e95c3a3dbb0316f1a4ad601ca8e330 SHA1 of 5f9ff671955a6d551595f9838aed063c496da5039be0d222fe84f96cb3e1d32a 2026-05-20