New DOUBLECUP ClickFix service hides malware in browser cache images
AI Summary
A Russian loader-as-a-service named DOUBLECUP has been active since June 2026, enabling threat actors to conduct ClickFix attacks by hiding malicious payloads in steganographic PNG images cached in victims' browsers. The service provides infrastructure for hosting malicious images, managing sessions, and delivering payloads, which include an updated CountLoader malware and a new Python-based RAT called DeviceManager. Victims are lured to malicious sites impersonating legitimate services like NetSuite and Salesforce, where fake CAPTCHA prompts trick them into executing commands that extract and run malware from the browser cache. DeviceManager uses blockchain smart contracts (EtherHiding) to dynamically retrieve C2 addresses, enhancing resilience against takedown efforts.
AI-extracted · verify before operational use