New DOUBLECUP ClickFix service hides malware in browser cache images
Russian loader-as-a-service DOUBLECUP uses ClickFix lures and steganographic PNG payloads cached by victims' browsers to deliver malware on both Windows and macOS—a novel evasion chain SOCs should prepare for.
Summary written by editorial AI · Source link below
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]
Editorial Analysis
The steganographic browser-cache technique evades conventional file and network inspection, requiring defenders to rethink where they look for payloads.
Update SOC playbooks to include browser-cache forensics and deploy IOCs for DOUBLECUP, CountLoader, and DeviceManager RAT.
A new malware-delivery service hides attacks inside cached browser images, evading traditional security controls on both Windows and Mac systems.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d