DOUBLECUP ClickFix service hides malware in cached PNGs

A newly exposed Russian loader-as-a-service operation dubbed DOUBLECUP is weaponizing ClickFix-style social engineering and steganographic PNG images cached by victims’ browsers to deliver an updated CountLoader strain and a previously undocumented remote access trojan known as DeviceManager.[1][6] Researchers at SOCRadar’s Threat Research Unit say DOUBLECUP has been active since early June 2026, providing turnkey infrastructure for customers to run these campaigns at scale.[1]

According to a recent analysis by BleepingComputer, DOUBLECUP sits on top of the broader ClickFix ecosystem, a technique in which malicious websites convince users to press Win+R, paste a command silently copied to the clipboard, and execute it, turning simple user interaction into code execution on the endpoint.[1][2][3] The DOUBLECUP service supplies operators with a Go-based Windows tool that generates the script they embed on compromised or malicious sites and handles hosting of steganographic PNGs, session and signal endpoints, encryption keys, and automatic rebuilding of payloads.[1]

Once a victim follows the ClickFix instructions, the first-stage DOUBLECUP code drops a specially crafted PNG image into the browser cache and extracts an encrypted payload concealed within its pixels, echoing earlier ClickFix campaigns that hid infostealer shellcode in PNGs using custom steganography routines.[1][2][3] The decrypted second-stage payload ultimately launches CountLoader, an evolved loader family now capable of targeting both Windows and macOS, harvesting detailed system information, checking for cryptocurrency wallets and Signal Desktop installations, establishing persistence via scheduled tasks, and downloading and executing additional payloads such as MSI packages, PowerShell modules and DLLs.[1][10]

In parallel, DOUBLECUP also deploys DeviceManager, a modular Python-based Windows RAT that researchers describe as previously undocumented and unusually resilient, leveraging an EtherHiding-style technique that queries Ethereum or Polygon smart contracts to determine the current command-and-control server address.[1][6] Analysis shows DeviceManager using DNS A and TXT records to exfiltrate host metadata, retrieve commands, stage new payloads, and return command output, while in non–Commonwealth of Independent States (CIS) countries it aggressively profiles infected machines by collecting identifiers, OS details, usernames, installed antivirus products and domain information.[1]

The DOUBLECUP activity underscores how ClickFix chains and steganographic loaders allow threat actors to bypass traditional defenses by abusing legitimate Windows utilities and browser caching rather than exploiting a specific software vulnerability, meaning there is no single CVE or vendor patch that neutralizes the threat.[2][3][7] Defenders are advised to harden endpoints by restricting or monitoring use of tools such as mshta.exe and PowerShell, scrutinizing traffic to content delivery networks hosting PNG assets, and considering policy-based controls that limit access to the Windows Run dialog—an approach previously recommended in ClickFix research from independent analysts—while pairing those technical controls with user education that explicitly warns against following “press Win+R and paste this command” instructions on the web.[2][3][7]

References

  1. New DOUBLECUP ClickFix service hides malware in …
  2. New ClickFix attacks abuse Windows App-V scripts to push …
  3. ClickFix Attack Hides Malware in Fake Windows Security …
  4. Lontz
  5. ClickFix Attack Uses Steganography to Hide Malicious Code in Fake …
  6. ClickFix malware uses steganography in AES-decrypted PNG images

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply