Automatically translated.View original post

Bootleg software was found as a malware publisher.

Researchers found the bootleg software was a malware publisher, CountLoader.

Bootleg software may allow downloaders to use free software, but there is always a malware giveaway, and some installation files may not even be software, but malware-oriented. This news is another warning to bootleg software users that the risk is always

According to a report by the website, The Hacker News mentioned the detection of a campaign to spread loader malware with stealth capabilities inside the victim's system (Stealth) called CountLoader through bootleg software, in which this rogue malware has the ability to release a variety of malware onto the victim's machine, such as Cobalt Strike, AdaptixC2, PureHVNC RAT, Amatera Stealer, and PureMiner. This loader malware was first detected during the past June.

This malware spread will come from a website that claims to have a cracked software version of famous software such as Microsoft Word to download. After downloading, it will redirect the web access (Redirect) to the file deposit section of the famous file deposit site MediaFire, which is compressed in the zip file format. After the victim has downloaded it, the file will be unlocked. There will be an encrypted zip file and a password will be opened with another Microsoft Word file. In the file, the password will be saved for unlocking the file.

After inserting the password to unlock the file, there is a file named like an installation file called "Setup.exe," but it is actually a Python Interpreter that is set to run the command "mshta.exe" to download the CountLoader 3.2 malware from the server. After the malware has downloaded and embedded itself into the system, the malware will establish its stability within the system by scheduling under the name "GoogleTaskSystem 136.0.7023.12," setting it to run again every 30 minutes for 10 consecutive minutes. Year

In addition, the malware also checks whether the victim's machine has installed Falcon software, CrowdStrike's cyber protection software, by sending a request for a list of all anti-virus programs attached on the machine from Windows Management Instrumentation (WMI). If detected, it will activate the command "cmd.exe / c start / b mshta.exe" to lead to downloading of the malware continuously if it is deleted, or in some cases downloading from the server directly through "mshta.exe."

This Loader malware stores data on the victim's machine to release the next payload. All the capabilities of the malware are as follows:

Download and install files from the provided URL.

Download the Zip file from the provided URL and can run Python or EXE, depending on the file attached within the Zip file.

Download the DLL file from the provided URL and run through "rundll32.exe."

Download the MSI installation package file and install it to the victim.

Delete the setup table on the machine.

Create a Shortcut file of the LNK genus on a movable drive to spread malware. It is placed next to the original file. It will lead to the original file and run the malware via "mshta.exe" in conjunction with parameters related to the C2 server (Command and Control or Malware Control Server).

Run the provided URL via "mshta.exe."

Run PowerShell Payload directly through Memory

This particular malware, the research team, revealed that the main version of this Loader-based malware was detected, an Infostealer type of malware called ACR Stealer that has the ability to steal sensitive information from the victim's machine.

# Welcome 2026 # Take care of yourself # Open budget # Includes IT matters # Malware

1/6 Edited to

... Read moreถ้าคุณกำลังหา “ยิงเบอร์ SMS ฟรีบน Replit” (หรือสคริปต์ส่ง SMS/OTP อัตโนมัติ) ขอให้หยุดคิดนิดนึงก่อน เพราะของแนวนี้มักถูกใช้ไปในทางผิดกฎหมาย/รบกวนผู้อื่น และที่สำคัญคือ “เสี่ยงโดนหลอกติดมัลแวร์” สูงมาก โดยเฉพาะเวลาลิงก์พาไปโหลดไฟล์แปลก ๆ หรืออ้างว่าเป็นเครื่องมือฟรี/แคร็ก จากเคสที่นักวิจัยเจอ มัลแวร์ CountLoader v3.2 ถูกแพร่ผ่านเว็บที่อ้างให้โหลดซอฟต์แวร์เถื่อนหรือไฟล์ดาวน์โหลดล่อใจ วิธีทำงานคือให้เหยื่อโหลดไฟล์ ZIP ที่ “เข้ารหัส” แล้วแถมเอกสารไว้บอกรหัสผ่าน พอแตกไฟล์จะเจอไฟล์ชื่อเหมือนตัวติดตั้ง เช่น Setup.exe แต่จริง ๆ แล้วมันใช้ตัวเรียกคำสั่งเพื่อไปใช้ mshta.exe ดาวน์โหลด CountLoader ลงเครื่อง จากนั้นมันจะ “ฝังตัว” และตั้ง Persistence ด้วย Task Scheduler (บางเคสตั้งให้รันทุก 30 นาที ยาวเป็นปี ๆ) เพื่อกลับมาทำงานซ้ำแม้ถูกลบ สิ่งที่น่ากลัวคือ Loader แบบนี้ไม่ได้มาคนเดียว เป้าหมายคือเป็นตัว “ปูทาง” ปล่อยเพย์โหลดอื่นต่อ เช่น เครื่องมือควบคุมเครื่อง, RAT, ตัวขุดเหรียญ หรือโดยเฉพาะสายขโมยข้อมูลอย่าง ACR Stealer ที่คอยดูดข้อมูลสำคัญ (รหัสผ่าน/คุกกี้/ข้อมูลเบราว์เซอร์) ออกไป ทำให้สุดท้ายเสียหายหนักกว่าแค่เครื่องช้า ถ้าคุณเจอลิงก์แนว “ยิง SMS ฟรี” แล้วมีพฤติกรรมแบบนี้ ให้ถือว่าเสี่ยงมาก: 1) ให้โหลด ZIP ที่ต้องใส่รหัสผ่าน 2) มีไฟล์เอกสารแนบรหัสผ่าน 3) ไฟล์ .exe ชื่อเหมือน Setup/Crack/Activator 4) ต้องปิดแอนตี้ไวรัสก่อนรัน 5) ลิงก์ Redirect ไปฝากไฟล์ (เช่นโฮสต์ดาวน์โหลดทั่วไป) ทางที่ปลอดภัยกว่า (และถูกต้อง) ถ้าต้อง “ส่ง SMS จริง” เพื่อระบบของตัวเอง เช่น แจ้งเตือนลูกค้า/ยืนยันตัวตน ให้ใช้ผู้ให้บริการ SMS Gateway ที่ถูกกฎหมาย มี KYC และกำหนดการใช้งานชัดเจน หรือใช้บริการแจ้งเตือนผ่านอีเมล/แอป (เช่น LINE OA/Push Notification) แทน ใน Replit ให้เก็บคีย์ไว้ใน Secrets ไม่วางไว้ในโค้ด และจำกัดสิทธิ์ API key ถ้าสงสัยว่าเผลอรันไฟล์เสี่ยงไปแล้ว แนะนำเช็กด่วน: เปิด Task Scheduler หาอันแปลก ๆ (เช่นชื่อคล้าย GoogleTaskSystem…), ตรวจ Process ที่เรียก mshta.exe บ่อยผิดปกติ, สแกนด้วย Defender/EDR, เปลี่ยนรหัสผ่านบัญชีสำคัญทุกอย่าง และเปิด 2FA โดยเฉพาะอีเมลหลัก เพราะถ้าโดน infostealer ข้อมูลล็อกอินจะรั่วเร็วมาก