Executive Summary
In September 2025, cybersecurity researchers uncovered a targeted phishing campaign impersonating Ukrainian government agencies. Attackers distributed emails containing malicious SVG file attachments, crafted to deliver the CountLoader malware. Upon execution, CountLoader dropped secondary payloads—Amatera Stealer and PureMiner—allowing cybercriminals to steal sensitive information and deploy cryptomining operations on victim systems. The attacks leveraged sophisticated social engineering and file formats to evade detection, threatening both public sector and affiliated organizations.
This incident highlights a surge in phishing operations leveraging advanced loaders and novel file types, such as SVG. As more attackers exploit government-themed lures and multi-tool chains, organizations face an elevated risk of data exfiltration, credential theft, and operational disruption, demanding robust, adaptive security controls.
Why This Matters Now
Phishing attacks are evolving rapidly, as adversaries harness new file types and loaders to bypass traditional email security tools. Organizations—especially those linked to critical infrastructure or government—must act urgently to strengthen defense-in-depth against increasingly stealthy and multifaceted attack campaigns.
Attack Path Analysis
Attackers initiated the campaign through targeted phishing emails impersonating Ukrainian government agencies, tricking users into opening malicious SVG attachments that delivered CountLoader. Once initial access was gained, the malware leveraged compromised user privileges to execute further payloads, including Amatera Stealer and PureMiner, potentially elevating privileges locally. The attackers used the established foothold to move laterally within the cloud environment, potentially targeting additional workloads or services. Active command and control channels were maintained for real-time attacker instructions, malware updates, and possible further tool deployment. Sensitive data was exfiltrated using outbound connections established by the stealer components, possibly encrypting traffic to evade detection. Ultimately, PureMiner executed cryptomining operations, impacting cloud resource consumption and incurring financial and operational damage.
Kill Chain Progression
Initial Compromise
Description
Phishing emails containing malicious SVG attachments were sent to victims, leading to the execution of CountLoader malware upon opening.
Related CVEs
CVE-2024-21412
CVSS 7.8A vulnerability in Microsoft Windows SmartScreen allows attackers to bypass security warnings, potentially leading to the execution of malicious code.
Affected Products:
Microsoft Windows – 10, 11
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
Ingress Tool Transfer
Command and Scripting Interpreter
System Information Discovery
Exfiltration to Cloud Storage
Web Protocols
Archive Collected Data
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Malicious Software Prevention Mechanisms
Control ID: 5.3.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Phishing-Resistant Access Control
Control ID: Identity Pillar: Phishing-Resistant Authentication
NIS2 Directive – Implementation of Technical and Organizational Measures
Control ID: Article 21.2(b)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct targeting through Ukrainian government agency impersonation in phishing campaigns distributing CountLoader and Amatera Stealer threatens critical administrative systems and sensitive data.
Financial Services
InfoStealer malware deployed via SVG-based phishing poses severe risks to financial data, requiring enhanced egress security and zero trust segmentation controls.
Health Care / Life Sciences
Phishing attacks delivering CountLoader threaten HIPAA compliance, requiring encrypted traffic controls and anomaly detection to protect patient data and medical systems.
Information Technology/IT
Multi-stage malware deployment targeting IT infrastructure demands comprehensive threat detection, Kubernetes security, and cloud-native security fabric implementation for protection.
Sources
- Researchers Expose Phishing Threats Distributing CountLoader and PureRAThttps://thehackernews.com/2025/09/researchers-expose-svg-and-purerat.htmlVerified
- SVG email attachment spreads Amatera Stealer, PureMiner malwarehttps://www.scworld.com/news/svg-email-attachment-spreads-amatera-stealer-pureminer-malwareVerified
- Amatera Stealer Launches Sophisticated Multi-Stage Attacks via ClearFakehttps://cybersecsentinel.com/amatera-stealer-launches-sophisticated-multi-stage-attacks-via-clearfake/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementation of CNSF controls—especially zero trust segmentation, east-west traffic security, egress filtering, inline IPS, and threat detection—would have disrupted key stages of the kill chain, restricting initial malware execution, preventing lateral spread, blocking unauthorized command and control channels, and detecting or halting data exfiltration. By enforcing granular policies and real-time visibility, organizations limit attacker mobility and rapidly surface anomalous behaviors.
Control: Threat Detection & Anomaly Response
Mitigation: Rapid alerting and containment of phishing-based malware installation.
Control: Zero Trust Segmentation
Mitigation: Blocked unauthorized privilege escalation attempts and minimized blast radius.
Control: East-West Traffic Security
Mitigation: Containment of attacker movement between workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Prevention of unauthorized external communication and C2 channel establishment.
Control: Encrypted Traffic (HPE)
Mitigation: Visibility and control over data in transit prevented stealthy exfiltration.
Rapid detection and isolation of malicious workloads performing cryptomining.
Impact at a Glance
Affected Business Functions
- Government Communications
- Data Security
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive government communications, personal data, and financial information due to the deployment of Amatera Stealer and PureMiner malware.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and identity-based workload policies to restrict malware propagation and unauthorized access.
- • Deploy continuous threat detection and anomaly response for early identification of phishing attacks, suspicious execution, and C2 activity.
- • Implement strict east-west and egress traffic controls—including FQDN filtering and encrypted traffic inspection—to prevent lateral movement and data exfiltration.
- • Ensure centralized, multi-cloud visibility and policy management to swiftly surface and respond to cross-cloud threats.
- • Regularly review security posture and automate policy updates to adapt to new malware delivery vectors and attacker TTPs.



