Skip to content

CountLoader

CountLoader is a multi-stage malware loader used to deliver follow-on payloads on Windows and, in newer observed variants, macOS.

Profile source: Mallory opens in a new tab

CountLoader

Family profile

CountLoader is a multi-stage malware loader used to deliver follow-on payloads on Windows and, in newer observed variants, macOS. It has been associated with professionally operated criminal campaigns and malware-as-a-service style operations, including delivery through the DOUBLECUP loader service. CountLoader commonly relies on heavily obfuscated staged execution chains involving HTA content, JavaScript, PowerShell, shellcode, and abuse of trusted system utilities such as MSHTA. Observed campaigns also used binary patching or masquerading of legitimate utilities to blend malicious execution with normal system activity.

On infected systems, CountLoader performs host profiling and reconnaissance, collecting operating system and security-product information, domain membership details, and other system metadata. Multiple reports show that it specifically searches for cryptocurrency wallet applications and browser wallet extensions, and some variants also check for the presence of Signal Desktop. Enterprise-focused variants include dedicated Active Directory reconnaissance modules that enumerate domain topology, groups, computers, and privilege-relevant information, making the malware relevant not only to consumer crypto theft but also to downstream lateral movement and broader compromise of domain-joined environments.

CountLoader establishes persistence on Windows through scheduled tasks and has also been observed using additional autorun mechanisms in some campaigns. The macOS variant uses LaunchAgent persistence and has been recovered in builds for both Intel and Apple Silicon systems. CountLoader can receive tasks from command-and-control infrastructure to download and execute additional payloads and components, including executables, DLLs, MSI packages, HTA content, PowerShell modules, and other files. Some campaigns linked to CountLoader ultimately deployed information stealers such as LummaStealer and Amatera, while others delivered cryptocurrency clippers or other secondary malware.

Delivery has varied across campaigns. Observed vectors include ClickFix-style social engineering with fake verification or CAPTCHA prompts, cracked-software and fake software-download lures, SEO-poisoning and social-media-driven traffic, removable-media propagation via malicious shortcut replacement, and disguised HTA or polyglot files using benign-looking extensions to evade filtering. CountLoader has also been distributed through trojanized installer themes such as fake CCleaner packages and through researcher-targeting lures themed as leaked source code.

The malware uses layered obfuscation, anti-analysis checks, fallback download methods, and fileless or in-memory execution to evade detection. Some related campaigns used environmental keying tied to victim-specific attributes, while others used blockchain-based techniques such as EtherHiding for resilient command-and-control discovery in downstream payload chains. CountLoader is best characterized as a flexible loader platform that bridges initial compromise, persistence, reconnaissance, and payload deployment, with recurring use in financially motivated operations targeting cryptocurrency assets and, in some cases, enterprise environments.

Capabilities

  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

Exploited software

Vulnerabilities linked to CountLoader

1 CVEs

MITRE ATT&CK

CountLoader in ATT&CK

66 distinct techniques

Techniques

66 techniques
T1059.005 Visual Basic T1204.002 Malicious File T1082 System Information Discovery T1543.001 Launch Agent T1027 Obfuscated Files or Information T1059.001 PowerShell T1204 User Execution T1059 Command and Scripting Interpreter T1027.003 Steganography T1518 Software Discovery T1053.005 Scheduled Task T1053 Scheduled Task/Job T1059.007 JavaScript T1566 Phishing T1105 Ingress Tool Transfer T1071 Application Layer Protocol T1036 Masquerading T1027.001 Binary Padding T1480.001 Environmental Keying T1568 Dynamic Resolution T1547.009 Shortcut Modification T1070 Indicator Removal T1041 Exfiltration Over C2 Channel T1115 Clipboard Data T1656 Impersonation T1055 Process Injection T1562.001 Disable or Modify Tools T1091 Replication Through Removable Media T1218.005 Mshta T1620 Reflective Code Loading T1564.003 Hidden Window T1573 Encrypted Channel T1566.002 Spearphishing Link T1189 Drive-by Compromise T1608.006 SEO Poisoning T1204.001 Malicious Link T1036.005 Match Legitimate Resource Name or Location T1140 Deobfuscate/Decode Files or Information T1574.001 DLL T1218.007 Msiexec T1608.001 Upload Malware T1018 Remote System Discovery T1566.001 Spearphishing Attachment T1583.001 Domains T1057 Process Discovery T1120 Peripheral Device Discovery T1573.002 Asymmetric Cryptography T1197 BITS Jobs T1027.006 HTML Smuggling T1497.001 System Checks T1071.001 Web Protocols T1568.002 Domain Generation Algorithms T1005 Data from Local System T1583.003 Virtual Private Server T1036.007 Double File Extension T1482 Domain Trust Discovery T1547.001 Registry Run Keys / Startup Folder T1614.001 System Language Discovery T1069.002 Domain Groups T1555.003 Credentials from Web Browsers T1087.002 Domain Account T1518.001 Security Software Discovery T1070.004 File Deletion T1059.003 Windows Command Shell T1218 System Binary Proxy Execution T1195.001 Compromise Software Dependencies and Development Tools

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.