#9
BleepingComputer
general
August 03, 2026 at 20:01 UTC
New DOUBLECUP ClickFix service hides malware in browser cache images
By Lawrence Abrams
AI Summary
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix lures to hide malicious code inside PNG images cached in victims' browsers, ultimately delivering CountLoader on both Windows and macOS and a new Windows-specific RAT called DeviceManager. The cross-platform delivery capability and use of browser cache as a steganographic staging mechanism represent a notable evasion technique that may bypass traditional file-based detection. Security teams should review browser cache monitoring and ClickFix-style social engineering defenses.
Relevance score: 76.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →