SYMBOLCOMMON_NAMEaka. SYNONYMS
win.count_loader (Back to overview)

CountLoader


According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript. They believe it is part of an IAB toolset or used by a affiliate with ties to LockBit, BlackBasta, and Qilin ransomware groups. CountLoader was also recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.

References
2026-08-03 ⋅ SOCRadar ⋅ SOCRadar
Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs
CountLoader
2025-12-18 ⋅ Cyderes ⋅ Rahul Ramesh
From Loader to Looter: ACR Stealer Rides on Upgraded CountLoader
ACR Stealer CountLoader
2025-09-18 ⋅ Silent Push ⋅ Silent Push
CountLoader: Silent Push Discovers New Malware Loader Being Served in 3 Different Versions
CountLoader

There is no Yara-Signature yet.