DeviceManager RAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
August 4, 2026
Last Seen
August 4, 2026

DeviceManager RAT is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.

DeviceManager RAT is a malware family tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed August 4, 2026; most recent activity August 4, 2026.

Related Threat Clusters

  • DOUBLECUP Service Delivers Malware via Cached PNG Images

    The DOUBLECUP loader-as-a-service, identified by SOCRadar, employs ClickFix attacks to conceal malware within PNG images cached by browsers. This service, operational since June 2026, targets Windows and macOS systems,…

    4 articles · Updated August 4, 2026

Recent Intelligence Reports

  • DOUBLECUP turns ClickFix into cached PNG delivery for CountLoader and DeviceManager — Feeds.4Sysops · August 4, 2026
  • DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT — Thehackernews · August 4, 2026

Frequently asked questions

What is DeviceManager RAT?

DeviceManager RAT is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.

Is DeviceManager RAT still active?

The most recent intelligence report mentioning DeviceManager RAT on ThreatCluster is dated August 4, 2026.

What is DeviceManager RAT associated with?

Across ThreatCluster reporting, DeviceManager RAT most frequently co-occurs with Doublecup, Malware, ClickFix, CountLoader.

What are the latest developments involving DeviceManager RAT?

The most significant recent cluster is “DOUBLECUP Service Delivers Malware via Cached PNG Images” (4 articles · Updated August 4, 2026). DeviceManager RAT appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on DeviceManager RAT?

DeviceManager RAT appears in 2 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown