Skip to content

Loader

CountLoader

According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript.

CountLoader is a Windows loader.

Background

Silent Push reports that this malware comes in several variants written in .NET, PowerShell, and JScript. Their assessment is that it forms part of an IAB toolset or is wielded by an affiliate connected to the LockBit, BlackBasta, and Qilin ransomware operations. CountLoader was also recently deployed in a PDF-themed phishing lure aimed at individuals in Ukraine, in a campaign that posed as the Ukrainian police.


Source: Malpedia (Fraunhofer FKIE).