← Back to Feed

New DOUBLECUP ClickFix service hides malware in browser cache images

August 3, 2026 · BleepingComputer · Severity: HIGH

A new Russian loader-as-a-service named DOUBLECUP employs ClickFix attacks to conceal malicious code within PNG images cached by victims' browsers. This technique ultimately delivers CountLoader to Windows and macOS devices, as well as a new remote access trojan called DeviceManager to Windows systems.

Key Takeaways

  • DOUBLECUP uses ClickFix attacks to hide malware in cached PNG images.
  • The service delivers CountLoader to Windows and macOS devices.
  • A new remote access trojan named DeviceManager targets Windows systems.
☕ Buy a Coffee