Back Feeds.4Sysops DOUBLECUP turns ClickFix into cached PNG delivery for CountLoader and DeviceManager
DOUBLECUP is using fake CRM pages and ClickFix instructions to hide malware inside PNG files cached by browsers. The loader delivers CountLoader or the newly documented DeviceManager RAT, which decrypts payloads in memory and can use blockchain-resolved command-and-control infrastructure. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
