← Back to Feed
New DOUBLECUP ClickFix service hides malware in browser cache images
August 3, 2026 · BleepingComputer · Severity: HIGH
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers. It ultimately delivers CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
Key Takeaways
- DOUBLECUP is a Russian loader-as-a-service using ClickFix attacks.
- Malicious code hides in PNG images cached by victims' browsers.
- Delivers CountLoader and DeviceManager trojans to Windows and macOS.