← Back to Feed
New DOUBLECUP ClickFix service hides malware in browser cache images
August 3, 2026 · BleepingComputer · Severity: HIGH
A new Russian loader-as-a-service named DOUBLECUP employs ClickFix attacks to conceal malicious code within PNG images cached by victims' browsers. This technique ultimately delivers CountLoader to Windows and macOS devices, as well as a new remote access trojan called DeviceManager to Windows systems.
Key Takeaways
- DOUBLECUP uses ClickFix attacks to hide malware in cached PNG images.
- The service delivers CountLoader to Windows and macOS devices.
- A new remote access trojan named DeviceManager targets Windows systems.