By Interestana AI Editorial — AI-drafted, human-overseen. How we report
DOUBLECUP Malware Uses ClickFix and Cached PNGs for RAT Delivery

A sophisticated Russian loader-as-a-service (LaaS) operation, identified by the codename DOUBLECUP, has been observed employing a novel technique to deliver malware. This operation utilizes ClickFix lures, a method designed to trick users into clicking on seemingly legitimate links, as a primary vector. Upon successful engagement with a ClickFix lure, DOUBLECUP stages malware-laced Portable Network Graphics (PNG) images directly within the victim's browser cache. This approach leverages the browser's caching mechanism to store and subsequently execute malicious payloads, bypassing traditional file system defenses.
The initial stage of the DOUBLECUP attack involves dropping a steganographic PNG image into the browser's cache. Steganography is the practice of concealing a file, message, application, or image within another file, message, application, or image. In this context, the malicious code is hidden within the visual data of the PNG file. Once the PNG is cached, the malware retrieves its hidden content. This retrieved content is then executed, initiating the second stage of the infection chain. The ultimate goal of this multi-stage process is to deliver two distinct types of malware: CountLoader and a previously undocumented remote access trojan (RAT) named DeviceManager.
CountLoader is a known loader malware that is designed to download and execute additional malicious payloads on an infected system. Its inclusion in the DOUBLECUP operation suggests a modular approach to infection, allowing attackers to adapt their strategy based on reconnaissance or desired outcomes. More significantly, the operation delivers DeviceManager, a newly discovered RAT. Remote access trojans grant attackers extensive control over an infected machine, enabling them to steal sensitive data, monitor user activity, deploy further malware, or use the compromised system as a pivot point for lateral movement within a network. The specific capabilities and functionalities of DeviceManager are still under investigation, but its presence indicates a significant new threat actor or an evolution in existing threat actor tactics.
The reliance on browser cache manipulation and steganography highlights the evolving tactics of cybercriminals to evade detection by security software. By embedding malicious code within image files and utilizing the browser's legitimate caching processes, DOUBLECUP aims to make its initial infection vectors harder to identify and block. This method can circumvent signature-based detection systems that primarily scan for known malicious files on disk. The use of ClickFix lures further complicates detection by masquerading malicious links as benign, potentially leading unsuspecting users to inadvertently download or execute the initial steganographic PNG. The full scope and impact of the DOUBLECUP operation, including the specific targets and the full range of DeviceManager's capabilities, are subjects of ongoing cybersecurity research.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.