CountLoader
CountLoader is a multi-stage malware loader used to deliver follow-on payloads on Windows and, in newer observed variants, macOS.
Profile source: Mallory opens in a new tabCountLoader
Family profile
CountLoader is a multi-stage malware loader used to deliver follow-on payloads on Windows and, in newer observed variants, macOS. It has been associated with professionally operated criminal campaigns and malware-as-a-service style operations, including delivery through the DOUBLECUP loader service. CountLoader commonly relies on heavily obfuscated staged execution chains involving HTA content, JavaScript, PowerShell, shellcode, and abuse of trusted system utilities such as MSHTA. Observed campaigns also used binary patching or masquerading of legitimate utilities to blend malicious execution with normal system activity.
On infected systems, CountLoader performs host profiling and reconnaissance, collecting operating system and security-product information, domain membership details, and other system metadata. Multiple reports show that it specifically searches for cryptocurrency wallet applications and browser wallet extensions, and some variants also check for the presence of Signal Desktop. Enterprise-focused variants include dedicated Active Directory reconnaissance modules that enumerate domain topology, groups, computers, and privilege-relevant information, making the malware relevant not only to consumer crypto theft but also to downstream lateral movement and broader compromise of domain-joined environments.
CountLoader establishes persistence on Windows through scheduled tasks and has also been observed using additional autorun mechanisms in some campaigns. The macOS variant uses LaunchAgent persistence and has been recovered in builds for both Intel and Apple Silicon systems. CountLoader can receive tasks from command-and-control infrastructure to download and execute additional payloads and components, including executables, DLLs, MSI packages, HTA content, PowerShell modules, and other files. Some campaigns linked to CountLoader ultimately deployed information stealers such as LummaStealer and Amatera, while others delivered cryptocurrency clippers or other secondary malware.
Delivery has varied across campaigns. Observed vectors include ClickFix-style social engineering with fake verification or CAPTCHA prompts, cracked-software and fake software-download lures, SEO-poisoning and social-media-driven traffic, removable-media propagation via malicious shortcut replacement, and disguised HTA or polyglot files using benign-looking extensions to evade filtering. CountLoader has also been distributed through trojanized installer themes such as fake CCleaner packages and through researcher-targeting lures themed as leaked source code.
The malware uses layered obfuscation, anti-analysis checks, fallback download methods, and fileless or in-memory execution to evade detection. Some related campaigns used environmental keying tied to victim-specific attributes, while others used blockchain-based techniques such as EtherHiding for resilient command-and-control discovery in downstream payload chains. CountLoader is best characterized as a flexible loader platform that bridges initial compromise, persistence, reconnaissance, and payload deployment, with recurring use in financially motivated operations targeting cryptocurrency assets and, in some cases, enterprise environments.
Capabilities
- Crypto Theft
- Defense Evasion
- Exfiltration
- Lateral Movement
- Persistence
- Post Exploitation
- Reconnaissance
Exploited software
Vulnerabilities linked to CountLoader
1 CVEsMITRE ATT&CK