DOUBLECUP Service Delivers Malware via Cached PNG Images

DOUBLECUP Service Delivers Malware via Cached PNG Images

First seen 4 Aug 2026, 14:23 UTC BleepingcomputerThehackernewsFeeds.4Sysopssocradar.io 80% similarity 66.5

Article Content

Browse articles
ThreatCluster

The DOUBLECUP loader-as-a-service, identified by SOCRadar, employs ClickFix attacks to conceal malware within PNG images cached by browsers. This service, operational since June 2026, targets Windows and macOS systems, delivering CountLoader and a new remote access trojan (RAT) named DeviceManager. Attackers use fake CAPTCHA prompts on legitimate-looking CRM pages to trick users into executing malicious commands. The method involves embedding malicious code in steganographic images, which are downloaded and executed from the browser cache. DOUBLECUP provides a Go-based tool for customers to configure and launch these campaigns, managing the necessary infrastructure for attacks. SOCRadar's investigation revealed the service's licensing panel hosted on a specific IP address, indicating organized operations. The impact is significant, affecting enterprise users of popular CRM platforms.

Key Points: • DOUBLECUP uses ClickFix attacks to hide malware in browser cache images. • The service delivers CountLoader and DeviceManager RAT to Windows and macOS systems. • Attackers exploit fake CRM login pages to trick users into executing malicious commands.

ThreatCluster AI How this analysis works

Timeline

2026-06-01
DOUBLECUP service launched
The DOUBLECUP loader-as-a-service began operations, providing tools for malware delivery.
Bleepingcomputer
2026-08-03
SOCRadar discovers DOUBLECUP
SOCRadar identified the DOUBLECUP service while investigating an open directory containing test files.
Bleepingcomputer
2026-08-04
DOUBLECUP malware delivery method reported
Reports confirmed that DOUBLECUP uses cached PNG images to deliver malware via ClickFix instructions.
Feeds.4Sysops
2026-08-04
DeviceManager RAT documented
The DeviceManager RAT, part of the DOUBLECUP payload, was detailed in recent cybersecurity reports.
Thehackernews

Community

Browse all →