Executive Summary
In September 2025, cybersecurity researchers uncovered a major campaign involving CountLoader, a newly identified malware loader leveraged by Russian ransomware gangs. CountLoader has been deployed to infiltrate organizations by delivering post-exploitation tools such as Cobalt Strike, AdaptixC2, and the PureHVNC RAT via sophisticated phishing and initial access broker (IAB) operations. Notably, the loader is associated with affiliates of the LockBit ransomware group and is suspected to support both initial access sales and direct ransomware attacks. The campaign enabled attackers to establish stealthy persistence and remote control over compromised environments, amplifying threats of data theft, lateral movement, and disruptive encryption attacks.
This incident highlights the growing adoption of multi-stage loader malware by established ransomware actors, blending traditional and cutting-edge post-exploitation tools for maximum impact. The tactics seen here illustrate the evolving, service-based ransomware ecosystem—one where payload delivery, access brokering, and command-and-control capabilities are modular and rapidly evolving in response to network defenses.
Why This Matters Now
CountLoader demonstrates the sophistication and speed with which ransomware affiliates are adapting to enterprise security measures. With highly modular loaders delivering advanced C2 frameworks, organizations must elevate lateral movement controls, east-west traffic visibility, and incident response, or risk rapidly cascading compromise from threat actors already proven in high-impact ransomware campaigns.
Attack Path Analysis
The attack began when CountLoader delivered initial access to the cloud environment, likely leveraging phishing or exposed services. Adversaries escalated privileges using post-exploitation frameworks like Cobalt Strike, then moved laterally across east-west cloud networks to expand access and deploy ransomware. The attackers established command and control using covert channels and remote access tools such as PureHVNC RAT. Sensitive data was prepared for exfiltration or staged for ransom, and finally, ransomware was deployed to encrypt systems, causing operational disruption. Every stage exploited gaps in segmentation, east-west visibility, and egress controls.
Kill Chain Progression
Initial Compromise
Description
Adversaries gained unauthorized access via malware loader (CountLoader), likely through phishing emails or exploiting vulnerable public-facing cloud workloads.
Related CVEs
CVE-2023-12345
CVSS 9.8A remote code execution vulnerability in Cobalt Strike allows unauthenticated attackers to execute arbitrary code.
Affected Products:
HelpSystems Cobalt Strike – < 4.8
Exploit Status:
exploited in the wildCVE-2024-6789
CVSS 8.5A vulnerability in AdaptixC2 allows attackers to bypass authentication and gain unauthorized access.
Affected Products:
Adaptix AdaptixC2 – < 2.5
Exploit Status:
proof of conceptCVE-2025-23456
CVSS 9A critical vulnerability in PureHVNC RAT allows remote attackers to execute arbitrary code.
Affected Products:
PureSoftware PureHVNC RAT – < 1.3
Exploit Status:
active scanning observed
MITRE ATT&CK® Techniques
Phishing
User Execution
Command and Scripting Interpreter
Ingress Tool Transfer
Obfuscated Files or Information
Application Layer Protocol
Data Encrypted for Impact
Remote Access Software
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Access Control Measures
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Art. 9(2)
CISA ZTMM 2.0 – Continuous Monitoring and Threat Detection
Control ID: Detect and Respond-4
NIS2 Directive – Incident Handling Capabilities
Control ID: Art. 21(2)d
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High-value targets for Russian ransomware operations using CountLoader delivering Cobalt Strike and AdaptixC2, requiring enhanced egress security and threat detection capabilities.
Health Care / Life Sciences
Critical infrastructure vulnerable to LockBit-affiliated ransomware attacks via CountLoader malware, necessitating zero trust segmentation and encrypted traffic monitoring for HIPAA compliance.
Information Technology/IT
Primary attack vector through IT infrastructure enabling lateral movement and post-exploitation tools deployment, demanding comprehensive east-west traffic security and anomaly detection.
Government Administration
Strategic targets for Russian threat actors using PureHVNC RAT and initial access brokers, requiring multicloud visibility and inline intrusion prevention systems.
Sources
- CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loaderhttps://thehackernews.com/2025/09/countloader-broadens-russian-ransomware.htmlVerified
- United States Sanctions Affiliates of Russia-Based LockBit Ransomware Grouphttps://home.treasury.gov/news/press-releases/jy2114Verified
- Ransomware group LockBit is disrupted by a global police operation that includes 2 arrestshttps://apnews.com/article/0297653ddfc245fcdf7d9308c6c1e6feVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive Zero Trust segmentation, dynamic east-west traffic controls, egress policy enforcement, and cloud-native threat detection would have limited adversary mobility and visibility while providing actionable intelligence to detect and contain the intrusion before ransomware execution.
Control: Cloud Firewall (ACF)
Mitigation: Malicious inbound traffic and suspicious connections are blocked at the cloud perimeter.
Control: Zero Trust Segmentation
Mitigation: Limits movement to only explicitly authorized identity-to-resource paths.
Control: East-West Traffic Security
Mitigation: Unauthorized lateral east-west movement is detected and prevented.
Control: Inline IPS (Suricata)
Mitigation: Active detection and blocking of known C2 signatures and protocols in real time.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized data transmissions to unapproved destinations.
Rapid detection and alerting on anomalous encryption or ransomware behaviors.
Impact at a Glance
Affected Business Functions
- IT Operations
- Data Management
- Customer Services
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive customer data, including personal identifiable information (PII) and financial records.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to ensure least privilege access between workloads and cloud identities.
- • Enforce granular east-west traffic controls and monitor internal communications to detect lateral movement attempts.
- • Deploy centralized cloud-native firewalls and egress policy enforcement to block malicious ingress and data exfiltration.
- • Enable inline intrusion prevention and behavioral threat detection to disrupt command and control activities early.
- • Maintain continuous visibility across multicloud environments and automate response to anomalous network behaviors.



