CountLoader
- Malware type
- downloader, loader
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:46:57
- Profile updated
- 2026-07-07 14:42:31
Targeted industries: government-and-public-sector
Targeted regions: country_code:ua
Context
According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript. They believe it is part of an IAB toolset or used by a affiliate with ties to LockBit, BlackBasta, and Qilin ransomware groups. CountLoader was also recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.
Reports & references
- cyderes.com — Acr Stealer Rides On Upgraded Countloader (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Count Loader (report)
- silentpush.com — Countloader (report)