CountLoader

Malware type
downloader, loader
Family
Malware family
Last IoC activity
2026-07-22 00:46:57
Profile updated
2026-07-07 14:42:31

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript. They believe it is part of an IAB toolset or used by a affiliate with ties to LockBit, BlackBasta, and Qilin ransomware groups. CountLoader was also recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.

Reports & references

  • cyderes.com — Acr Stealer Rides On Upgraded Countloader (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Count Loader (report)
  • silentpush.com — Countloader (report)

External references