A new Russian loader-as-a-service platform called DOUBLECUP is utilizing ClickFix lures and steganographic images to distribute CountLoader and the DeviceManager remote access trojan to unsuspecting Windows and macOS users.
Key Points
- DOUBLECUP has been active since June 2026, providing operators with a license-based panel to manage malware campaigns and payload delivery.
- The attack chain uses steganographic PNG images hidden in browser caches to execute malicious scripts, including JavaScript, VBScript, and PowerShell.
- Payloads are decrypted in memory using environmental keying, which utilizes the victim's public IP address as a cryptographic seed to prevent unauthorized analysis.
- CountLoader targets both Windows and macOS, while the Python-based DeviceManager uses EtherHiding to resolve command-and-control infrastructure via blockchain smart contracts.
- Campaigns impersonate legitimate CRM login pages for services like Salesforce, HubSpot, and NetSuite to trick users into executing malicious ClickFix commands.