Dossier
CountLoader
Coverage of CountLoader in the Nexus archive.
- New DOUBLECUP ClickFix service hides malware in browser cache images
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
- Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
A malware-as-a-service campaign named Weedhack is targeting Minecraft players via YouTube, spreading malware through pirated content. The campaign, active since January 2026, impersonates Minecraft clients and mods to infect users, with CountLoader malware affecting 86,000 devices.