Bottom line: The LaaS campaign DOUBLECUP hides malicious code in PNG images stored in the browser cache and uses ClickFix deception to deliver the CountLoader loader as well as the new RAT DeviceManager.
A new Russian-speaking Loader-as-a-Service operation named DOUBLECUP relies on ClickFix social engineering to plant manipulated PNG images in victims’ browser caches and uses them to deliver CountLoader as well as a previously unknown remote access trojan called DeviceManager.
According to reports, the first stage of the DOUBLECUP attack drops a steganographically prepared PNG image into the browser’s cache. Hidden code is extracted from this image and executed, initiating the second stage of the attack. The campaign relies on ClickFix lure tactics, in which victims are tricked via fake error messages or verification dialogs into manually executing commands that trigger the infection process. At the end of the infection chain are two known or newly identified pieces of malware: the already documented loader CountLoader, and DeviceManager, a previously undisclosed remote access trojan (RAT).
For security professionals, the combination of ClickFix and steganography in cache files is significant because it bypasses classic signature-based detection and URL filtering: the actual malicious functionality is not located in visible network traffic or in an obviously malicious file, but is hidden inside a seemingly harmless image that ends up on the system through regular browser caching mechanisms. Since ClickFix attacks rely on user interaction, the human remains the decisive attack vector, regardless of the technical concealment of the subsequent payload.
For defense, a combination of user awareness training against ClickFix patterns — such as prompts to use key combinations like Win+R or to paste commands from purported error messages — and technical monitoring of PowerShell or script executions initiated from browser cache directories is recommended. Since CountLoader is already known from previous campaigns, existing indicators and detection rules for this loader can serve as a starting point, while DeviceManager, as a new RAT, will require additional dedicated detection logic once technical indicators for it are published.
Source: thehackernews.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.