← Back to Feed

New DOUBLECUP ClickFix service hides malware in browser cache images

August 3, 2026 · BleepingComputer · Severity: HIGH

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers. It ultimately delivers CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.

Key Takeaways

  • DOUBLECUP is a Russian loader-as-a-service using ClickFix attacks.
  • Malicious code hides in PNG images cached by victims' browsers.
  • Delivers CountLoader and DeviceManager trojans to Windows and macOS.
☕ Buy a Coffee