Feeds.4Sysops DOUBLECUP Service Delivers Malware via Cached PNG Images
Article Content
- •DOUBLECUP uses ClickFix attacks to hide malware in browser cache images.
- •The service delivers CountLoader and DeviceManager RAT to Windows and macOS systems.
- •Attackers exploit fake CRM login pages to trick users into executing malicious commands.
The DOUBLECUP loader-as-a-service, identified by SOCRadar, employs ClickFix attacks to conceal malware within PNG images cached by browsers. This service, operational since June 2026, targets Windows and macOS systems, delivering CountLoader and a new remote access trojan (RAT) named DeviceManager. Attackers use fake CAPTCHA prompts on legitimate-looking CRM pages to trick users into executing malicious commands. The method involves embedding malicious code in steganographic images, which are downloaded and executed from the browser cache. DOUBLECUP provides a Go-based tool for customers to configure and launch these campaigns, managing the necessary infrastructure for attacks. SOCRadar's investigation revealed the service's licensing panel hosted on a specific IP address, indicating organized operations. The impact is significant, affecting enterprise users of popular CRM platforms.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Doublecup, CountLoader and Hubspot in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…