importantSYS.SOURCE: The Hacker News• 2026-08-04T14:33:23+05:30
DOUBLECUP Malware Campaign Utilizes ClickFix and Cached PNGs for RAT Delivery
DOUBLECUP employs steganographic PNGs in browser caches and custom encryption to deliver CountLoader and DeviceManager RAT, utilizing Ethereum for C2 communication. The malware uses environmental keying and browser-specific payloads to evade detection and establish persistence on targeted systems.
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
"The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second
*** END OF TRANSMISSION ***