Feeds.4Sysops
DOUBLECUP Service Delivers Malware via Cached PNG Images
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The DOUBLECUP loader-as-a-service, identified by SOCRadar, employs ClickFix attacks to conceal malware within PNG images cached by browsers. This service, operational since June 2026, targets Windows and macOS systems, delivering CountLoader and a new remote access trojan (RAT) named DeviceManager. Attackers use fake CAPTCHA prompts on legitimate-looking CRM pages to trick users into executing malicious commands. The method involves embedding malicious code in steganographic images, which are downloaded and executed from the browser cache. DOUBLECUP provides a Go-based tool for customers to configure and launch these campaigns, managing the necessary infrastructure for attacks. SOCRadar's investigation revealed the service's licensing panel hosted on a specific IP address, indicating organized operations. The impact is significant, affecting enterprise users of popular CRM platforms.
Key Points: • DOUBLECUP uses ClickFix attacks to hide malware in browser cache images. • The service delivers CountLoader and DeviceManager RAT to Windows and macOS systems. • Attackers exploit fake CRM login pages to trick users into executing malicious commands.