Toggle light / dark theme

New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.

SOCRadar’s Threat Research Unit says DOUBLECUP has operated since early June 2026, providing customers with licenses and a Go-based Windows tool for creating malicious campaigns and generating the code operators add to their websites.

The service handles much of the infrastructure required to conduct the attacks, including hosting the steganographic PNG images, managing session and signal endpoints, providing encryption keys, and automatically rebuilding payloads.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */