Utopia Tech
SecurityAI-assisted1 min read

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A newly identified Russian loader-as-a-service called DOUBLECUP is leveraging ClickFix social engineering tactics to hide malicious payloads within PNG images stored in browser caches. The attack chain uses steganography to conceal malware code, ultimately deploying CountLoader and a previously unknown remote access trojan named DeviceManager RAT.

UT

Utopia Tech

August 4, 2026 · 1 min read

Share

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content