bleeping-computer · Crawled Aug 3, 2026

New DOUBLECUP ClickFix service hides malware in browser cache images

3 IoCs 1 Malware
Read original article ↗

AI Summary

A Russian loader-as-a-service named DOUBLECUP has been active since June 2026, enabling threat actors to conduct ClickFix attacks by hiding malicious payloads in steganographic PNG images cached in victims' browsers. The service provides infrastructure for hosting malicious images, managing sessions, and delivering payloads, which include an updated CountLoader malware and a new Python-based RAT called DeviceManager. Victims are lured to malicious sites impersonating legitimate services like NetSuite and Salesforce, where fake CAPTCHA prompts trick them into executing commands that extract and run malware from the browser cache. DeviceManager uses blockchain smart contracts (EtherHiding) to dynamically retrieve C2 addresses, enhancing resilience against takedown efforts.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 3 extracted

Type Value Detail
IP 213[.]139[.]77[.]109 Details →
Filename findstr Details →
Filename certutil Details →

MITRE ATT&CK TTPs 9 techniques