DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.

“The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the second

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Attack Update: Top 5 Attack-IPs auf doode.info – 30.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 406 requests (recent log) 34.26.62.24 — 280 requests (recent log) 136.66.143.67 — 260 requests (recent

Attack Update: Top 5 Attack-IPs auf doode.info – 06.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 137 requests (recent log) 216.244.66.232 — 25 requests (recent log) 216.73.217.85 — 22 requests (recent

Attack Update: Top 5 Attack-IPs auf doode.info – 04.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 515 requests (recent log) 216.244.66.232 — 130 requests (recent log) 216.73.216.125 — 110 requests (recent