By Interestana AI Editorial — AI-drafted, human-overseen. How we report
DOUBLECUP Loader Hides Malware in Browser Cache Images
A newly identified Russian loader-as-a-service, dubbed DOUBLECUP, is employing a technique known as ClickFix attacks to conceal malicious code within PNG images that are cached by victims' web browsers. This sophisticated method allows the malware to bypass traditional security measures by embedding itself in seemingly innocuous image files. Once the malicious PNG is loaded into the browser's cache, the malware can be executed on the victim's system. The primary payload delivered by DOUBLECUP is CountLoader, a known malware strain that has been adapted to infect both Windows and macOS devices. In addition to CountLoader, DOUBLECUP also deploys a novel remote access trojan (RAT) specifically for Windows systems, named DeviceManager. This RAT grants attackers extensive control over infected machines, enabling them to steal data, monitor user activity, and potentially deploy further malicious payloads. The ClickFix attack vector is particularly concerning as it leverages the legitimate functionality of browser caching, making it difficult for security software to distinguish between safe and malicious files. Researchers first observed DOUBLECUP's operations in early 2024, noting its consistent evolution and adaptation to evade detection. The service is believed to be operated by Russian-speaking threat actors, though specific attribution remains challenging. The use of a loader-as-a-service model suggests a professionalized cybercrime operation, where different components of the attack chain are developed and sold to other malicious actors. This modular approach allows for greater flexibility and scalability in their operations. The deployment of CountLoader, a well-established infostealer, indicates a focus on financial gain and credential harvesting. CountLoader is known to exfiltrate sensitive information such as login credentials, financial data, and system information from infected machines. The introduction of the DeviceManager RAT for Windows further expands the capabilities of the DOUBLECUP campaign, providing attackers with persistent access and remote control over compromised systems. This allows for more targeted and advanced attacks, including espionage and data exfiltration. Security analysts are urging users to maintain updated antivirus software and to be cautious about downloading files from untrusted sources, even if they appear to be common image files. The complexity of the DOUBLECUP attack highlights the ongoing innovation within the cybercrime landscape and the need for continuous vigilance and advanced threat detection capabilities.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.