Skip to content
DOUBLECUP Service Delivers Malware via Cached PNG Images

DOUBLECUP Service Delivers Malware via Cached PNG Images

First seen 4 Aug 2026, 14:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 5, 2026 at 14:09 UTC

The DOUBLECUP loader-as-a-service, identified by SOCRadar, employs ClickFix attacks to conceal malware within PNG images cached by browsers. This service, operational since June 2026, targets Windows and macOS systems, delivering CountLoader and a new remote access trojan (RAT) named DeviceManager. Attackers use fake CAPTCHA prompts on legitimate-looking CRM pages to trick users into executing malicious commands. The method involves embedding malicious code in steganographic images, which are downloaded and executed from the browser cache. DOUBLECUP provides a Go-based tool for customers to configure and launch these campaigns, managing the necessary infrastructure for attacks. SOCRadar's investigation revealed the service's licensing panel hosted on a specific IP address, indicating organized operations. The impact is significant, affecting enterprise users of popular CRM platforms.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2026-06-01
DOUBLECUP service launched
The DOUBLECUP loader-as-a-service began operations, providing tools for malware delivery.
Bleepingcomputer
2026-08-03
SOCRadar discovers DOUBLECUP
SOCRadar identified the DOUBLECUP service while investigating an open directory containing test files.
Bleepingcomputer
2026-08-04
DOUBLECUP malware delivery method reported
Reports confirmed that DOUBLECUP uses cached PNG images to deliver malware via ClickFix instructions.
Feeds.4Sysops
2026-08-04
DeviceManager RAT documented
The DeviceManager RAT, part of the DOUBLECUP payload, was detailed in recent cybersecurity reports.
Thehackernews

More articles in this cluster (4)

Following this threat?

Track Doublecup, CountLoader and Hubspot in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed