DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
- ID
- 10625
- Status
- summarized
- Published
- 04 Aug 2026, 5:03 PM
- Fetched
- 04 Aug 2026, 6:20 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Excerpt
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second
Summary
No summary yet. It will appear after the daemon summarizes this item.