ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

DOUBLECUP ClickFix loader smuggles malware via cached PNG browser images

Source headline: New DOUBLECUP ClickFix service hides malware in browser cache images

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

A Russian loader-as-a-service called DOUBLECUP uses ClickFix techniques to hide malicious payloads inside PNG images stored in victims' browser caches. The approach allows malware to be delivered without obvious file downloads during the initial infection flow. Victims can end up with the CountLoader malware on both Windows and macOS systems. On Windows, the same campaign also delivers a new remote access trojan named DeviceManager. Users should keep browsers and systems patched and watch for suspicious activity that could indicate loader behavior.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#malware #remote-access-trojan #clickfix #browser-cache #png-steganography #russian-loader
Original reporting BleepingComputer New DOUBLECUP ClickFix service hides malware in browser cache images
Open original source