AUTO-UPDATED

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service platform called DOUBLECUP is utilizing ClickFix lures and steganographic images to distribute CountLoader and the DeviceManager remote access trojan to unsuspecting Windows and macOS users.

Key Points

  • DOUBLECUP has been active since June 2026, providing operators with a license-based panel to manage malware campaigns and payload delivery.
  • The attack chain uses steganographic PNG images hidden in browser caches to execute malicious scripts, including JavaScript, VBScript, and PowerShell.
  • Payloads are decrypted in memory using environmental keying, which utilizes the victim's public IP address as a cryptographic seed to prevent unauthorized analysis.
  • CountLoader targets both Windows and macOS, while the Python-based DeviceManager uses EtherHiding to resolve command-and-control infrastructure via blockchain smart contracts.
  • Campaigns impersonate legitimate CRM login pages for services like Salesforce, HubSpot, and NetSuite to trick users into executing malicious ClickFix commands.

Why it Matters

This loader-as-a-service model lowers the barrier to entry for cybercriminals by providing a sophisticated, automated pipeline for malware distribution and evasion. The use of blockchain-based infrastructure and environmental keying demonstrates an increasing trend toward resilient, highly targeted attacks that are difficult for traditional security tools to detect.
Internet Published by info@thehackernews.com (The Hacker News)
Read original