Skip to content

New Loader-as-a-Service DOUBLECUP Hides Malware in Browser Cache Images

Bottom line: DOUBLECUP smuggles malicious code into browsers via cached PNG images to install CountLoader and the new RAT DeviceManager.

A Russian loader-as-a-service called DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images that are stored in victims’ browser cache. This delivers the CountLoader loader to Windows and macOS devices, as well as a new remote access trojan called DeviceManager to Windows systems.

DOUBLECUP is a newly identified loader-as-a-service originating from the Russian-speaking cybercrime scene. The attackers rely on the ClickFix technique, in which victims are tricked via manipulated websites or fake error messages into executing malicious commands themselves — for example by copying and pasting supposed troubleshooting steps into the command line. What sets DOUBLECUP apart is its obfuscation method: the actual malicious code is embedded in PNG image files that are routinely cached by the browser. These cached images serve as carriers for the payload, allowing them to evade classic detection mechanisms that focus on unusual file types or network connections.

Through this mechanism, DOUBLECUP first delivers the already known CountLoader loader, which works on both Windows and macOS systems. In a second step, a new remote access trojan named DeviceManager is installed on Windows devices, giving attackers persistent remote access to infected systems.

For security professionals, the relevant point is that DOUBLECUP represents a further evolution of the ClickFix attack method, which has increasingly been adopted by various criminal groups as an entry vector since its emergence. The use of browser cache images to conceal malicious code further complicates detection by signature-based security solutions and network monitoring, since the traffic appears at first glance to be normal loading of web content.

Organizations should intensify employee training on ClickFix patterns, as the attack relies on social engineering rather than technical exploits. In addition, it is advisable to check whether endpoint detection solutions can identify unusual command-line activity typically associated with ClickFix chains, regardless of how the payload is ultimately disguised.


Source: www.bleepingcomputer.com · Published August 3, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: