VMTech
Discuss a project

DOUBLECUP Uses Cached PNGs to Deploy CountLoader and DeviceManager

DOUBLECUP Uses Cached PNGs to Deploy CountLoader and DeviceManager

SOCRadar has identified DOUBLECUP, a Russian loader-as-a-service active since early June 2026 that uses ClickFix lures and malware-laced PNG images cached by a victim's browser. The delivery chain installs Windows and macOS variants of CountLoader or a previously undocumented, Python-based remote access trojan called DeviceManager.

The service gives operators licenses and a Go-based Windows client for creating campaigns, configuring payloads, and embedding the necessary code in ClickFix landing pages. Each license has a unique key and metadata including the client's IP address, active days, label, and version, while supporting multiple campaigns.

How the browser cache becomes a staging area

Operators configure a domain, slug, steganography method, embed type, archive format, action, and payload URLs. DOUBLECUP then generates an API endpoint that returns the image URL, image size, session endpoint, and commands tailored to Chrome, Edge, Firefox, Brave, or Opera.

The landing page fetches that configuration, prefetches the steganographic image, registers a session, and checks the browser User-Agent. It shows ClickFix instructions and copies a matching command to the clipboard. The command searches the browser cache for the PNG and extracts malicious JavaScript, VBScript, or PowerShell to launch the next stage.

This delivery model extends the broader evolution of ClickFix attack chains by turning a cached image and a user-executed command into a browser-specific staging chain.

The second stage deploys an encrypted payload and redirects the victim to another page. It uses environmental keying: the target's public IPv4 address seeds a key derivation function, producing the key needed to decode the payload. Decryption therefore fails on a machine with a different address.

CountLoader expands across Windows and macOS

CountLoader establishes persistence with scheduled tasks, inventories browser extensions associated with cryptocurrency wallets, and checks whether the Signal desktop application is installed. Its Windows build can also scan browser shortcuts and rewrite their targets to launch both the browser and the RAT, although SOCRadar found that function was not invoked.

The loader collects and exfiltrates system metadata, then waits for tasks. It can run executables, DLLs, MSI packages, and HTA files, or download an archive, extract it, and execute its main binary. An equivalent macOS variant adapts persistence and reconnaissance to Apple's operating system.

DeviceManager resolves infrastructure through smart contracts

DeviceManager arrives in a Delphi-compiled Inno Setup installer containing an encrypted payload and a complete Python environment. It uses EtherHiding to retrieve active command-and-control nodes from Ethereum or Polygon smart contracts, then communicates over HTTP or DNS tunneling.

The RAT collects device information, runs PowerShell and Python scripts, passes commands to cmd.exe, downloads payloads, and reports task results. It also checks system language settings and, when it detects a Commonwealth of Independent States locale, removes its scheduled task and installation directory before terminating.

Business implications

Organizations should treat instructions that ask users to paste or execute browser-supplied commands as a security event rather than a routine verification step. Endpoint monitoring should correlate browser activity with launches of PowerShell, VBScript, JavaScript, Python, or cmd.exe, while network controls should examine unexpected DNS tunneling and HTTP callbacks. Because DOUBLECUP combines social engineering, browser caching, steganography, and target-bound decryption, effective defense depends on visibility across the full chain rather than on inspecting the final payload alone.

#cybersecurity#malware#clickfix#threatintel
Open analytics
On the site 0 views
min read 4 05.08.2026
Instagram

DOUBLECUP Uses Cached PNGs to Deploy CountLoader and DeviceManager

Open the post on Instagram ↗