Skip to content

CountLoader

CountLoader is a multi-stage malware loader targeting Windows, with later variants also targeting macOS.

Profile source: Mallory opens in a new tab

CountLoader

Family profile

CountLoader is a multi-stage malware loader targeting Windows, with later variants also targeting macOS. It commonly uses obfuscated HTA and JavaScript executed through MSHTA, PowerShell, and in-memory shellcode execution to retrieve and launch follow-on payloads. Observed payloads include information stealers, cryptocurrency clippers, and other secondary malware.

CountLoader profiles infected hosts, collecting operating-system, hardware, security-product, domain-membership, browser-extension, cryptocurrency-wallet, and Signal Desktop information. It uses a custom encrypted command-and-control protocol and JWT-authenticated tasking to download or execute executables, DLLs, MSI packages, HTA content, PowerShell, and other payloads. Windows variants establish persistence through scheduled tasks; macOS variants use LaunchAgents. Some variants evade analysis by checking sandbox or security-product artifacts, altering execution chains based on endpoint security products, deleting artifacts, and executing payloads in memory.

Campaigns have distributed CountLoader through trojanized and cracked software downloads, SEO-poisoned or fraudulent software sites, malicious archives containing abused legitimate Python components, disguised HTML Applications, removable media, and ClickFix lures. In ClickFix operations, it has been delivered through browser-cached steganographic images and fake verification prompts. CountLoader can propagate through removable drives by replacing files with malicious shortcut files. Its wallet and browser-extension reconnaissance, Active Directory reconnaissance capability, and flexible secondary-payload delivery make it relevant to both cryptocurrency theft and enterprise post-compromise activity.

Capabilities

  • Crypto Theft
  • Defense Evasion
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance

Exploited software

Vulnerabilities linked to CountLoader

1 CVEs

MITRE ATT&CK

CountLoader in ATT&CK

70 distinct techniques

Techniques

70 techniques
T1204.002 Malicious File T1047 Windows Management Instrumentation T1218.011 Rundll32 T1218.005 Mshta T1059.001 PowerShell T1218.007 Msiexec T1518.001 Security Software Discovery T1091 Replication Through Removable Media T1482 Domain Trust Discovery T1204.001 Malicious Link T1053.005 Scheduled Task T1132.001 Standard Encoding T1071.001 Web Protocols T1069.002 Domain Groups T1087.002 Domain Account T1132.002 Non-Standard Encoding T1041 Exfiltration Over C2 Channel T1197 BITS Jobs T1059.005 Visual Basic T1082 System Information Discovery T1543.001 Launch Agent T1027 Obfuscated Files or Information T1204 User Execution T1059 Command and Scripting Interpreter T1027.003 Steganography T1518 Software Discovery T1053 Scheduled Task/Job T1059.007 JavaScript T1566 Phishing T1105 Ingress Tool Transfer T1071 Application Layer Protocol T1036 Masquerading T1027.001 Binary Padding T1480.001 Environmental Keying T1568 Dynamic Resolution T1547.009 Shortcut Modification T1070 Indicator Removal T1115 Clipboard Data T1656 Impersonation T1055 Process Injection T1562.001 Disable or Modify Tools T1620 Reflective Code Loading T1564.003 Hidden Window T1573 Encrypted Channel T1566.002 Spearphishing Link T1189 Drive-by Compromise T1608.006 SEO Poisoning T1036.005 Match Legitimate Resource Name or Location T1140 Deobfuscate/Decode Files or Information T1574.001 DLL T1608.001 Upload Malware T1018 Remote System Discovery T1566.001 Spearphishing Attachment T1583.001 Domains T1057 Process Discovery T1120 Peripheral Device Discovery T1573.002 Asymmetric Cryptography T1027.006 HTML Smuggling T1497.001 System Checks T1568.002 Domain Generation Algorithms T1005 Data from Local System T1583.003 Virtual Private Server T1036.007 Double File Extension T1547.001 Registry Run Keys / Startup Folder T1614.001 System Language Discovery T1555.003 Credentials from Web Browsers T1070.004 File Deletion T1059.003 Windows Command Shell T1218 System Binary Proxy Execution T1195.001 Compromise Software Dependencies and Development Tools

Reporting

Research mentioning CountLoader

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.