DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.

“The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the second

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

How to disable or avoid intrusive AI

How to disable or avoid intrusive AI Source: Hacker News

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549)

Attack Update: Top 5 Attack-IPs auf doode.info – 05.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 β€” 162 requests (recent log) 216.244.66.232 β€” 51 requests (recent log) 152.89.170.191 β€” 49 requests (recent