CountLoader is a malware family delivered via DOUBLECUP, with Windows and macOS variants. It establishes persistence via scheduled tasks, audits browser extensions for crypto wallets, and profiles the host for Signal. It can execute secondary payloads and clean up forensic evidence.