Home / Aug 04, 2026 / Story
0
#9 BleepingComputer general August 03, 2026 at 20:01 UTC

New DOUBLECUP ClickFix service hides malware in browser cache images

By Lawrence Abrams

AI Summary

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix lures to hide malicious code inside PNG images cached in victims' browsers, ultimately delivering CountLoader on both Windows and macOS and a new Windows-specific RAT called DeviceManager. The cross-platform delivery capability and use of browser cache as a steganographic staging mechanism represent a notable evasion technique that may bypass traditional file-based detection. Security teams should review browser cache monitoring and ClickFix-style social engineering defenses.

Relevance score: 76.0/100

# More from August 04