ShellCodeX Intelligence Brief
HIGH
Cybersecurity
DOUBLECUP ClickFix loader smuggles malware via cached PNG browser images
Source headline: New DOUBLECUP ClickFix service hides malware in browser cache images
Threat level
High
Signal strength
75/100
Source confidence
1 source
Published
1 hour ago
Intelligence Summary
A Russian loader-as-a-service called DOUBLECUP uses ClickFix techniques to hide malicious payloads inside PNG images stored in victims' browser caches. The approach allows malware to be delivered without obvious file downloads during the initial infection flow. Victims can end up with the CountLoader malware on both Windows and macOS systems. On Windows, the same campaign also delivers a new remote access trojan named DeviceManager. Users should keep browsers and systems patched and watch for suspicious activity that could indicate loader behavior.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
BleepingComputer
New DOUBLECUP ClickFix service hides malware in browser cache images
Open original source