New DOUBLECUP ClickFix service hides malware in browser cache images

New DOUBLECUP ClickFix service hides malware in browser cache images
DOUBLECUP is a new Russian loader-as-a-service that uses ClickFix lures and PNG steganography to hide code in browser cache and deliver CountLoader plus the DeviceManager RAT. SOCRadar says the service has been active since early June 2026, with campaigns impersonating NetSuite, Odoo, HubSpot, and Salesforce to trick victims into running malicious commands. #DOUBLECUP #CountLoader #DeviceManager #SOCRadar

Keypoints

  • DOUBLECUP hides malicious code inside PNG images cached by victim browsers.
  • The service uses ClickFix prompts on fake login pages to trick users into executing commands.
  • Operators get infrastructure support for hosting images, sessions, keys, and payload rebuilding.
  • DOUBLECUP delivers CountLoader to Windows and macOS and DeviceManager to Windows.
  • DeviceManager uses EtherHiding and blockchain smart contracts to locate its C2 server.

Read More: https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/