DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.

“The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the second

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

The Burau representation of the braid group is faithful for n = 4

The Burau representation of the braid group is faithful for n = 4 Source: Hacker News

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April

Mesh LLM: distributed AI computing on iroh

Mesh LLM: distributed AI computing on iroh Source: Hacker News